CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4673  CVE-2002-0281  Candidate  Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php.  Modified (20050710)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:dcpportal-userupdate-css(8197)  View
3255  CVE-2001-0437  Candidate  upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.  Interim (20010911)  ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:dcforum-az-file-upload(6393)  View
3254  CVE-2001-0436  Candidate  dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.  Interim (20010911)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:dcforum-az-expr(6392)  View
3102  CVE-2001-0281  Candidate  Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.  Proposed (20010404)  MODIFY(1) Frech | NOOP(2) Cole, Ziese | REVIEWING(2) Bishop, Wall  Frech> XF:dbgprint-format-string(6441)  View
4012  CVE-2001-1208  Candidate  Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.  Proposed (20020315)  MODIFY(1) Frech | NOOP(5) Cole, Foat, Green, Wall, Ziese  Frech> XF:daydream-bbs-format-string(9120)  View

Page 186 of 20943, showing 5 records out of 104715 total, starting on record 926, ending on 930

Actions