CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8225  CVE-2003-1401  Candidate  login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.  Assigned (20071019)  None (candidate not yet proposed)    View
8224  CVE-2003-1400  Candidate  Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.  Assigned (20071018)  None (candidate not yet proposed)    View
8223  CVE-2003-1399  Candidate  eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.  Assigned (20071018)  None (candidate not yet proposed)    View
8222  CVE-2003-1398  Candidate  Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).  Assigned (20071018)  None (candidate not yet proposed)    View
8221  CVE-2003-1397  Candidate  The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.  Assigned (20071018)  None (candidate not yet proposed)    View

Page 19299 of 20943, showing 5 records out of 104715 total, starting on record 96491, ending on 96495

Actions