CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10079  CVE-2004-1651  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.  Assigned (20050221)  None (candidate not yet proposed)    View
10080  CVE-2004-1652  Candidate  phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.  Assigned (20050221)  None (candidate not yet proposed)    View
10081  CVE-2004-1653  Candidate  The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.  Assigned (20050221)  None (candidate not yet proposed)    View
10082  CVE-2004-1654  Candidate  SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.  Assigned (20050221)  None (candidate not yet proposed)    View
10083  CVE-2004-1655  Candidate  Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 19721 of 20943, showing 5 records out of 104715 total, starting on record 98601, ending on 98605

Actions