CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8035  CVE-2003-1211  Candidate  Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.  Assigned (20050519)  None (candidate not yet proposed)    View
8034  CVE-2003-1210  Candidate  Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.  Assigned (20050519)  None (candidate not yet proposed)    View
8033  CVE-2003-1209  Candidate  The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.  Assigned (20050519)  None (candidate not yet proposed)    View
8032  CVE-2003-1208  Candidate  Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.  Assigned (20050519)  None (candidate not yet proposed)    View
8031  CVE-2003-1207  Candidate  Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.  Assigned (20050519)  None (candidate not yet proposed)    View

Page 19337 of 20943, showing 5 records out of 104715 total, starting on record 96681, ending on 96685

Actions