CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6415  CVE-2002-2033  Candidate  faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00).  Assigned (20050714)  None (candidate not yet proposed)    View
6414  CVE-2002-2032  Candidate  sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.  Assigned (20050714)  None (candidate not yet proposed)    View
6413  CVE-2002-2031  Candidate  Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results.  Assigned (20050714)  None (candidate not yet proposed)    View
6412  CVE-2002-2030  Candidate  Stack-based buffer overflow in SQLData Enterprise Server 3.0 allows remote attacker to execute arbitrary code and cause a denial of service via a long HTTP request.  Assigned (20050714)  None (candidate not yet proposed)    View
6411  CVE-2002-2029  Candidate  PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 19661 of 20943, showing 5 records out of 104715 total, starting on record 98301, ending on 98305

Actions