CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8165  CVE-2003-1341  Candidate  The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.  Assigned (20071014)  None (candidate not yet proposed)    View
8164  CVE-2003-1340  Candidate  Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.  Assigned (20070930)  None (candidate not yet proposed)    View
8163  CVE-2003-1339  Candidate  Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.  Assigned (20070923)  None (candidate not yet proposed)    View
8162  CVE-2003-1338  Candidate  CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.  Assigned (20070923)  None (candidate not yet proposed)    View
8161  CVE-2003-1337  Candidate  Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.  Assigned (20070923)  None (candidate not yet proposed)    View

Page 19311 of 20943, showing 5 records out of 104715 total, starting on record 96551, ending on 96555

Actions