CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6068  CVE-2002-1684  Candidate  Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.  Assigned (20050621)  None (candidate not yet proposed)    View
13236  CVE-2005-2030  Candidate  Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.  Assigned (20050621)  None (candidate not yet proposed)    View
6069  CVE-2002-1685  Candidate  Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.  Assigned (20050621)  None (candidate not yet proposed)    View
13237  CVE-2005-2031  Candidate  Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtopic.php, the (5) secid or (6) artid parameter to sections.php, (7) siteid parameter to index.php, or (8) sid parameter to friend.php.  Assigned (20050621)  None (candidate not yet proposed)    View
6070  CVE-2002-1686  Candidate  Buffer overflow in lscfg of unknown versions of AIX has unknown impact.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19248 of 20943, showing 5 records out of 104715 total, starting on record 96236, ending on 96240

Actions