CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10252 | CVE-2004-1825 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10253 | CVE-2004-1826 | Candidate | SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10254 | CVE-2004-1827 | Candidate | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10255 | CVE-2004-1828 | Candidate | Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10256 | CVE-2004-1829 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19405 of 20943, showing 5 records out of 104715 total, starting on record 97021, ending on 97025