CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6705  CVE-2002-2323  Candidate  Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.  Assigned (20071026)  None (candidate not yet proposed)    View
6704  CVE-2002-2322  Candidate  Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.  Assigned (20071026)  None (candidate not yet proposed)    View
6703  CVE-2002-2321  Candidate  Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.  Assigned (20071026)  None (candidate not yet proposed)    View
6702  CVE-2002-2320  Candidate  MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.  Assigned (20071026)  None (candidate not yet proposed)    View
6701  CVE-2002-2319  Candidate  Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.  Assigned (20071026)  None (candidate not yet proposed)    View

Page 19603 of 20943, showing 5 records out of 104715 total, starting on record 98011, ending on 98015

Actions