CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6415 | CVE-2002-2033 | Candidate | faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00). | Assigned (20050714) | None (candidate not yet proposed) | View | |
6414 | CVE-2002-2032 | Candidate | sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6413 | CVE-2002-2031 | Candidate | Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6412 | CVE-2002-2030 | Candidate | Stack-based buffer overflow in SQLData Enterprise Server 3.0 allows remote attacker to execute arbitrary code and cause a denial of service via a long HTTP request. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6411 | CVE-2002-2029 | Candidate | PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 19661 of 20943, showing 5 records out of 104715 total, starting on record 98301, ending on 98305