CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8250  CVE-2003-1426  Candidate  Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl"s @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.  Assigned (20071019)  None (candidate not yet proposed)    View
8249  CVE-2003-1425  Candidate  guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.  Assigned (20071019)  None (candidate not yet proposed)    View
8248  CVE-2003-1424  Candidate  message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.  Assigned (20071019)  None (candidate not yet proposed)    View
8247  CVE-2003-1423  Candidate  Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.  Assigned (20071019)  None (candidate not yet proposed)    View
8246  CVE-2003-1422  Candidate  Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.  Assigned (20071019)  None (candidate not yet proposed)    View

Page 19294 of 20943, showing 5 records out of 104715 total, starting on record 96466, ending on 96470

Actions