CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4673 | CVE-2002-0281 | Candidate | Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php. | Modified (20050710) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:dcpportal-userupdate-css(8197) | View |
3255 | CVE-2001-0437 | Candidate | upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file. | Interim (20010911) | ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:dcforum-az-file-upload(6393) | View |
3254 | CVE-2001-0436 | Candidate | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. | Interim (20010911) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:dcforum-az-expr(6392) | View |
3102 | CVE-2001-0281 | Candidate | Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges. | Proposed (20010404) | MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(2) Bishop, Wall | Frech> XF:dbgprint-format-string(6441) | View |
4012 | CVE-2001-1208 | Candidate | Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code. | Proposed (20020315) | MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese | Frech> XF:daydream-bbs-format-string(9120) | View |
Page 186 of 20943, showing 5 records out of 104715 total, starting on record 926, ending on 930