CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10266  CVE-2004-1839  Candidate  MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View
7963  CVE-2003-1139  Candidate  Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.  Assigned (20050504)  None (candidate not yet proposed)    View
10267  CVE-2004-1840  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.  Assigned (20050504)  None (candidate not yet proposed)    View
7964  CVE-2003-1140  Candidate  Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.  Assigned (20050504)  None (candidate not yet proposed)    View
10268  CVE-2004-1841  Candidate  SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19409 of 20943, showing 5 records out of 104715 total, starting on record 97041, ending on 97045

Actions