CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6550 | CVE-2002-2168 | Candidate | SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6549 | CVE-2002-2167 | Candidate | Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6548 | CVE-2002-2166 | Candidate | Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6547 | CVE-2002-2165 | Candidate | The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser"s previous login session in an error page, which allows local users to read another user"s inbox. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6546 | CVE-2002-2164 | Candidate | Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 19634 of 20943, showing 5 records out of 104715 total, starting on record 98166, ending on 98170