CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6031 | CVE-2002-1647 | Candidate | The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords by reading the username and password from the Referrer URL. | Assigned (20050328) | None (candidate not yet proposed) | View | |
6032 | CVE-2002-1648 | Candidate | Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters. | Assigned (20050328) | None (candidate not yet proposed) | View | |
6033 | CVE-2002-1649 | Candidate | Cross-site scripting (XSS) vulnerability in read_body.php in SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary Javascript via a javascript: URL in an IMG tag. | Assigned (20050328) | None (candidate not yet proposed) | View | |
6034 | CVE-2002-1650 | Candidate | The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspell_command parameter. | Assigned (20050328) | None (candidate not yet proposed) | View | |
12072 | CVE-2005-0866 | Candidate | cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files. | Assigned (20050326) | None (candidate not yet proposed) | View |
Page 19605 of 20943, showing 5 records out of 104715 total, starting on record 98021, ending on 98025