CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8034 | CVE-2003-1210 | Candidate | Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function. | Assigned (20050519) | None (candidate not yet proposed) | View | |
8035 | CVE-2003-1211 | Candidate | Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter. | Assigned (20050519) | None (candidate not yet proposed) | View | |
8036 | CVE-2003-1212 | Candidate | MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the "start new topic" HTML page. | Assigned (20050519) | None (candidate not yet proposed) | View | |
8037 | CVE-2003-1213 | Candidate | The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb. | Assigned (20050519) | None (candidate not yet proposed) | View | |
8038 | CVE-2003-1214 | Candidate | Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions. | Assigned (20050519) | None (candidate not yet proposed) | View |
Page 19357 of 20943, showing 5 records out of 104715 total, starting on record 96781, ending on 96785