CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8075 | CVE-2003-1251 | Candidate | The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6540 | CVE-2002-2158 | Candidate | zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8076 | CVE-2003-1252 | Candidate | register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6541 | CVE-2002-2159 | Candidate | Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers go gain access. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8077 | CVE-2003-1253 | Candidate | PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 18728 of 20943, showing 5 records out of 104715 total, starting on record 93636, ending on 93640