CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10607 | CVE-2004-2181 | Candidate | Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65. | Assigned (20050711) | REVIEWING(1) Christey | Christey> The view_user.php/sort_by vector is covered by several CVEs. | Need to figure out how to handle this. | View |
10608 | CVE-2004-2182 | Candidate | Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10609 | CVE-2004-2183 | Candidate | Unknown vulnerability in WeHelpBUS 0.1 allows remote attackers to execute arbitrary shell commands via the query string. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10610 | CVE-2004-2184 | Candidate | Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write arbitrary files via "../" or ".." sequences in commands such as (1) dir or (2) put. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10611 | CVE-2004-2185 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow remote attackers to execute arbitrary scripts and/or SQL queries via (1) the UnicodeConverter extension, (2) raw page views, (3) SpecialIpblocklist, (4) SpecialEmailuser, (5) SpecialMaintenance, and (6) ImagePage. | Assigned (20050711) | None (candidate not yet proposed) | View |
Page 1791 of 20943, showing 5 records out of 104715 total, starting on record 8951, ending on 8955