CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11180  CVE-2004-2754  Candidate  SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.  Assigned (20071115)  None (candidate not yet proposed)    View
11179  CVE-2004-2753  Candidate  Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to access unspecified files or cause a denial of service via unknown vectors related to handling of "files in a potentially insecure manner."  Assigned (20071113)  None (candidate not yet proposed)    View
11178  CVE-2004-2752  Candidate  Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.  Assigned (20071113)  None (candidate not yet proposed)    View
11177  CVE-2004-2751  Candidate  SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.  Assigned (20071113)  None (candidate not yet proposed)    View
11176  CVE-2004-2750  Candidate  Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20071113)  None (candidate not yet proposed)    View

Page 18708 of 20943, showing 5 records out of 104715 total, starting on record 93536, ending on 93540

Actions