CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7415  CVE-2003-0588  Candidate  admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View
7414  CVE-2003-0587  Candidate  Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.  Assigned (20030717)  None (candidate not yet proposed)    View
7413  CVE-2003-0586  Candidate  Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.  Assigned (20030717)  None (candidate not yet proposed)    View
7412  CVE-2003-0585  Candidate  SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.  Assigned (20030717)  None (candidate not yet proposed)    View
7411  CVE-2003-0584  Candidate  Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.  Assigned (20030717)  None (candidate not yet proposed)    View

Page 19461 of 20943, showing 5 records out of 104715 total, starting on record 97301, ending on 97305

Actions