CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6110  CVE-2002-1728  Candidate  askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.  Assigned (20050621)  None (candidate not yet proposed)    View
6109  CVE-2002-1727  Candidate  Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.  Assigned (20050621)  None (candidate not yet proposed)    View
6108  CVE-2002-1726  Candidate  secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.  Assigned (20050621)  None (candidate not yet proposed)    View
6107  CVE-2002-1725  Candidate  phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function.  Assigned (20050621)  None (candidate not yet proposed)    View
6106  CVE-2002-1724  Candidate  Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.  Assigned (20050621)  None (candidate not yet proposed)    View

Page 19722 of 20943, showing 5 records out of 104715 total, starting on record 98606, ending on 98610

Actions