CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10468  CVE-2004-2042  Candidate  Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10213  CVE-2004-1785  Candidate  SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.  Assigned (20050504)  None (candidate not yet proposed)    View
10469  CVE-2004-2043  Candidate  Buffer overflow in ibserver for Firebird Database 1.0 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows remote attackers to cause a denial of service (crash) via a long database name, as demonstrated using the gsec command.  Assigned (20050504)  None (candidate not yet proposed)    View
10214  CVE-2004-1786  Candidate  PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.  Assigned (20050504)  None (candidate not yet proposed)    View
10470  CVE-2004-2044  Candidate  PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER["PHP_SELF"] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19464 of 20943, showing 5 records out of 104715 total, starting on record 97316, ending on 97320

Actions