CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10291 | CVE-2004-1864 | Candidate | SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
7988 | CVE-2003-1164 | Candidate | Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10292 | CVE-2004-1865 | Candidate | Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability. | Assigned (20050504) | None (candidate not yet proposed) | View | |
7989 | CVE-2003-1165 | Candidate | Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10293 | CVE-2004-1866 | Candidate | nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19419 of 20943, showing 5 records out of 104715 total, starting on record 97091, ending on 97095