CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6107  CVE-2002-1725  Candidate  phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function.  Assigned (20050621)  None (candidate not yet proposed)    View
6108  CVE-2002-1726  Candidate  secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.  Assigned (20050621)  None (candidate not yet proposed)    View
6109  CVE-2002-1727  Candidate  Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.  Assigned (20050621)  None (candidate not yet proposed)    View
6110  CVE-2002-1728  Candidate  askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.  Assigned (20050621)  None (candidate not yet proposed)    View
6111  CVE-2002-1729  Candidate  Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19264 of 20943, showing 5 records out of 104715 total, starting on record 96316, ending on 96320

Actions