CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10357 | CVE-2004-1930 | Candidate | Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10358 | CVE-2004-1932 | Candidate | SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10359 | CVE-2004-1933 | Candidate | Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10360 | CVE-2004-1934 | Candidate | PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10361 | CVE-2004-1935 | Candidate | Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19440 of 20943, showing 5 records out of 104715 total, starting on record 97196, ending on 97200