CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5865 | CVE-2002-1481 | Candidate | savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View | |
5864 | CVE-2002-1480 | Candidate | Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry. | Proposed (20030317) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View | |
5863 | CVE-2002-1479 | Entry | Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users modify databases as the Cacti user and possibly gain privileges. | View | |||
5862 | CVE-2002-1478 | Entry | Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. | View | |||
5861 | CVE-2002-1477 | Entry | graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode. | View |
Page 19771 of 20943, showing 5 records out of 104715 total, starting on record 98851, ending on 98855