CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8000  CVE-2003-1176  Candidate  post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10304  CVE-2004-1877  Candidate  The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.  Assigned (20050504)  None (candidate not yet proposed)    View
8001  CVE-2003-1177  Candidate  Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.  Assigned (20050504)  None (candidate not yet proposed)    View
10305  CVE-2004-1878  Candidate  LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).  Assigned (20050504)  None (candidate not yet proposed)    View
8002  CVE-2003-1178  Candidate  Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19424 of 20943, showing 5 records out of 104715 total, starting on record 97116, ending on 97120

Actions