CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10270 | CVE-2004-1843 | Candidate | SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10269 | CVE-2004-1842 | Candidate | Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10268 | CVE-2004-1841 | Candidate | SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10267 | CVE-2004-1840 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10266 | CVE-2004-1839 | Candidate | MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 18890 of 20943, showing 5 records out of 104715 total, starting on record 94446, ending on 94450