CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10270  CVE-2004-1843  Candidate  SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.  Assigned (20050504)  None (candidate not yet proposed)    View
10269  CVE-2004-1842  Candidate  Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10268  CVE-2004-1841  Candidate  SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.  Assigned (20050504)  None (candidate not yet proposed)    View
10267  CVE-2004-1840  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10266  CVE-2004-1839  Candidate  MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18890 of 20943, showing 5 records out of 104715 total, starting on record 94446, ending on 94450

Actions