CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8070  CVE-2003-1246  Candidate  NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on winntsystem32drivers using the subst command.  Assigned (20051116)  None (candidate not yet proposed)    View
8069  CVE-2003-1245  Candidate  index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.  Assigned (20051116)  None (candidate not yet proposed)    View
8068  CVE-2003-1244  Candidate  SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.  Assigned (20051116)  None (candidate not yet proposed)    View
8067  CVE-2003-1243  Candidate  Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.  Assigned (20051116)  None (candidate not yet proposed)    View
8066  CVE-2003-1242  Candidate  Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 19330 of 20943, showing 5 records out of 104715 total, starting on record 96646, ending on 96650

Actions