CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7415 | CVE-2003-0588 | Candidate | admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password. | Assigned (20030717) | None (candidate not yet proposed) | View | |
7414 | CVE-2003-0587 | Candidate | Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie. | Assigned (20030717) | None (candidate not yet proposed) | View | |
7413 | CVE-2003-0586 | Candidate | Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php. | Assigned (20030717) | None (candidate not yet proposed) | View | |
7412 | CVE-2003-0585 | Candidate | SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters. | Assigned (20030717) | None (candidate not yet proposed) | View | |
7411 | CVE-2003-0584 | Candidate | Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument. | Assigned (20030717) | None (candidate not yet proposed) | View |
Page 19461 of 20943, showing 5 records out of 104715 total, starting on record 97301, ending on 97305