CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8225 | CVE-2003-1401 | Candidate | login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8224 | CVE-2003-1400 | Candidate | Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter. | Assigned (20071018) | None (candidate not yet proposed) | View | |
8223 | CVE-2003-1399 | Candidate | eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information. | Assigned (20071018) | None (candidate not yet proposed) | View | |
8222 | CVE-2003-1398 | Candidate | Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification). | Assigned (20071018) | None (candidate not yet proposed) | View | |
8221 | CVE-2003-1397 | Candidate | The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method. | Assigned (20071018) | None (candidate not yet proposed) | View |
Page 19299 of 20943, showing 5 records out of 104715 total, starting on record 96491, ending on 96495