CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6332 | CVE-2002-1950 | Candidate | Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6333 | CVE-2002-1951 | Candidate | Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6334 | CVE-2002-1952 | Candidate | phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6335 | CVE-2002-1953 | Candidate | Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy. | Assigned (20050629) | None (candidate not yet proposed) | View | |
6336 | CVE-2002-1954 | Candidate | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 1743 of 20943, showing 5 records out of 104715 total, starting on record 8711, ending on 8715