CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6560  CVE-2002-2178  Candidate  Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.  Assigned (20051116)  None (candidate not yet proposed)    View
6559  CVE-2002-2177  Candidate  BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.  Assigned (20051116)  None (candidate not yet proposed)    View
6558  CVE-2002-2176  Candidate  SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.  Assigned (20051116)  None (candidate not yet proposed)    View
6557  CVE-2002-2175  Candidate  phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username.  Assigned (20051116)  None (candidate not yet proposed)    View
6556  CVE-2002-2174  Candidate  The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 19632 of 20943, showing 5 records out of 104715 total, starting on record 98156, ending on 98160

Actions