CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10776 | CVE-2004-2350 | Candidate | SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10777 | CVE-2004-2351 | Candidate | Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10778 | CVE-2004-2352 | Candidate | Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10779 | CVE-2004-2353 | Candidate | BugPort before 1.099 stores its configuration file (conf/config.conf) under the web document root with a file extension that is not normally parsed by web servers, which allows remote attackers to obtain sensitive information. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10780 | CVE-2004-2354 | Candidate | SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered. | Assigned (20050816) | None (candidate not yet proposed) | View |
Page 18996 of 20943, showing 5 records out of 104715 total, starting on record 94976, ending on 94980