CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10425 | CVE-2004-1999 | Candidate | Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10424 | CVE-2004-1998 | Candidate | The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10423 | CVE-2004-1997 | Candidate | Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10422 | CVE-2004-1996 | Candidate | Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10421 | CVE-2004-1995 | Candidate | Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 18859 of 20943, showing 5 records out of 104715 total, starting on record 94291, ending on 94295