CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10607  CVE-2004-2181  Candidate  Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.  Assigned (20050711)  REVIEWING(1) Christey  Christey> The view_user.php/sort_by vector is covered by several CVEs. | Need to figure out how to handle this.  View
10608  CVE-2004-2182  Candidate  Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.  Assigned (20050711)  None (candidate not yet proposed)    View
10609  CVE-2004-2183  Candidate  Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string.  Assigned (20050711)  None (candidate not yet proposed)    View
10610  CVE-2004-2184  Candidate  Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or ".." sequences in commands such as (1) dir or (2) put.  Assigned (20050711)  None (candidate not yet proposed)    View
10611  CVE-2004-2185  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow remote attackers to execute arbitrary scripts and/or SQL queries via (1) the UnicodeConverter extension, (2) raw page views, (3) SpecialIpblocklist, (4) SpecialEmailuser, (5) SpecialMaintenance, and (6) ImagePage.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 1791 of 20943, showing 5 records out of 104715 total, starting on record 8951, ending on 8955

Actions