CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6332  CVE-2002-1950  Candidate  Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.  Assigned (20050629)  None (candidate not yet proposed)    View
6333  CVE-2002-1951  Candidate  Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.  Assigned (20050629)  None (candidate not yet proposed)    View
6334  CVE-2002-1952  Candidate  phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.  Assigned (20050629)  None (candidate not yet proposed)    View
6335  CVE-2002-1953  Candidate  Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.  Assigned (20050629)  None (candidate not yet proposed)    View
6336  CVE-2002-1954  Candidate  Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 1743 of 20943, showing 5 records out of 104715 total, starting on record 8711, ending on 8715

Actions