CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8250 | CVE-2003-1426 | Candidate | Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl"s @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8249 | CVE-2003-1425 | Candidate | guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8248 | CVE-2003-1424 | Candidate | message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8247 | CVE-2003-1423 | Candidate | Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8246 | CVE-2003-1422 | Candidate | Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors. | Assigned (20071019) | None (candidate not yet proposed) | View |
Page 19294 of 20943, showing 5 records out of 104715 total, starting on record 96466, ending on 96470