CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8040  CVE-2003-1216  Candidate  SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
8039  CVE-2003-1215  Candidate  SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
8038  CVE-2003-1214  Candidate  Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.  Assigned (20050519)  None (candidate not yet proposed)    View
8037  CVE-2003-1213  Candidate  The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.  Assigned (20050519)  None (candidate not yet proposed)    View
8036  CVE-2003-1212  Candidate  MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the "start new topic" HTML page.  Assigned (20050519)  None (candidate not yet proposed)    View

Page 19336 of 20943, showing 5 records out of 104715 total, starting on record 96676, ending on 96680

Actions