CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10255  CVE-2004-1828  Candidate  Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10254  CVE-2004-1827  Candidate  Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.  Assigned (20050504)  None (candidate not yet proposed)    View
10253  CVE-2004-1826  Candidate  SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10252  CVE-2004-1825  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10251  CVE-2004-1824  Candidate  Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18893 of 20943, showing 5 records out of 104715 total, starting on record 94461, ending on 94465

Actions