CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10006  CVE-2004-1578  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.  Assigned (20050220)  None (candidate not yet proposed)    View
10007  CVE-2004-1579  Candidate  index.php in CubeCart 2.0.1 allows remote attackers to gain sensitive information via an HTTP request with an invalid cat_id parameter, which reveals the full path in a PHP error message.  Assigned (20050220)  None (candidate not yet proposed)    View
10008  CVE-2004-1580  Candidate  SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.  Assigned (20050220)  None (candidate not yet proposed)    View
10009  CVE-2004-1581  Candidate  BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.  Assigned (20050220)  None (candidate not yet proposed)    View
10010  CVE-2004-1582  Candidate  PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 19739 of 20943, showing 5 records out of 104715 total, starting on record 98691, ending on 98695

Actions