CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10776  CVE-2004-2350  Candidate  SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter.  Assigned (20050816)  None (candidate not yet proposed)    View
10777  CVE-2004-2351  Candidate  Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.  Assigned (20050816)  None (candidate not yet proposed)    View
10778  CVE-2004-2352  Candidate  Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke.  Assigned (20050816)  None (candidate not yet proposed)    View
10779  CVE-2004-2353  Candidate  BugPort before 1.099 stores its configuration file (conf/config.conf) under the web document root with a file extension that is not normally parsed by web servers, which allows remote attackers to obtain sensitive information.  Assigned (20050816)  None (candidate not yet proposed)    View
10780  CVE-2004-2354  Candidate  SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.  Assigned (20050816)  None (candidate not yet proposed)    View

Page 18996 of 20943, showing 5 records out of 104715 total, starting on record 94976, ending on 94980

Actions