CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7970  CVE-2003-1146  Candidate  Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10274  CVE-2004-1847  Candidate  News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.  Assigned (20050504)  None (candidate not yet proposed)    View
7971  CVE-2003-1147  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0955. Reason: This candidate is a duplicate of CVE-2003-0955. Notes: All CVE users should reference CVE-2003-0955 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050504)  None (candidate not yet proposed)    View
10275  CVE-2004-1848  Candidate  Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.  Assigned (20050504)  None (candidate not yet proposed)    View
7972  CVE-2003-1148  Candidate  Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19412 of 20943, showing 5 records out of 104715 total, starting on record 97056, ending on 97060

Actions