CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10255 | CVE-2004-1828 | Candidate | Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10254 | CVE-2004-1827 | Candidate | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10253 | CVE-2004-1826 | Candidate | SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10252 | CVE-2004-1825 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10251 | CVE-2004-1824 | Candidate | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 18893 of 20943, showing 5 records out of 104715 total, starting on record 94461, ending on 94465