CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10306  CVE-2004-1879  Candidate  Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.  Assigned (20050504)  None (candidate not yet proposed)    View
8003  CVE-2003-1179  Candidate  Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10307  CVE-2004-1880  Candidate  Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).  Assigned (20050504)  None (candidate not yet proposed)    View
8004  CVE-2003-1180  Candidate  Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10308  CVE-2004-1881  Candidate  SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19425 of 20943, showing 5 records out of 104715 total, starting on record 97121, ending on 97125

Actions