CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10357  CVE-2004-1930  Candidate  Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.  Assigned (20050504)  None (candidate not yet proposed)    View
10358  CVE-2004-1932  Candidate  SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10359  CVE-2004-1933  Candidate  Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.  Assigned (20050504)  None (candidate not yet proposed)    View
10360  CVE-2004-1934  Candidate  PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10361  CVE-2004-1935  Candidate  Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19440 of 20943, showing 5 records out of 104715 total, starting on record 97196, ending on 97200

Actions