CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9960 | CVE-2004-1532 | Candidate | AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9959 | CVE-2004-1531 | Candidate | SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9958 | CVE-2004-1530 | Candidate | SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9957 | CVE-2004-1529 | Candidate | Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9956 | CVE-2004-1528 | Candidate | The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message. | Assigned (20050218) | None (candidate not yet proposed) | View |
Page 18952 of 20943, showing 5 records out of 104715 total, starting on record 94756, ending on 94760