CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8065 | CVE-2003-1241 | Candidate | Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8064 | CVE-2003-1240 | Candidate | PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8063 | CVE-2003-1239 | Candidate | Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8062 | CVE-2003-1238 | Candidate | Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8061 | CVE-2003-1237 | Candidate | Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 19331 of 20943, showing 5 records out of 104715 total, starting on record 96651, ending on 96655