CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9960  CVE-2004-1532  Candidate  AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.  Assigned (20050218)  None (candidate not yet proposed)    View
9959  CVE-2004-1531  Candidate  SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.  Assigned (20050218)  None (candidate not yet proposed)    View
9958  CVE-2004-1530  Candidate  SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.  Assigned (20050218)  None (candidate not yet proposed)    View
9957  CVE-2004-1529  Candidate  Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.  Assigned (20050218)  None (candidate not yet proposed)    View
9956  CVE-2004-1528  Candidate  The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.  Assigned (20050218)  None (candidate not yet proposed)    View

Page 18952 of 20943, showing 5 records out of 104715 total, starting on record 94756, ending on 94760

Actions