CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8210  CVE-2003-1386  Candidate  AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server"s /var/log/messages file.  Assigned (20071018)  None (candidate not yet proposed)    View
8209  CVE-2003-1385  Candidate  ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.  Assigned (20071018)  None (candidate not yet proposed)    View
8208  CVE-2003-1384  Candidate  Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.  Assigned (20071018)  None (candidate not yet proposed)    View
8207  CVE-2003-1383  Candidate  WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.  Assigned (20071018)  None (candidate not yet proposed)    View
8206  CVE-2003-1382  Candidate  Buffer overflow in ISMail 1.4.3 and earlier allow remote attackers to execute arbitrary code via long domain names in (1) MAIL FROM or (2) RCPT TO fields.  Assigned (20071018)  None (candidate not yet proposed)    View

Page 19302 of 20943, showing 5 records out of 104715 total, starting on record 96506, ending on 96510

Actions