CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5865  CVE-2002-1481  Candidate  savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
5864  CVE-2002-1480  Candidate  Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.  Proposed (20030317)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
5863  CVE-2002-1479  Entry  Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users modify databases as the Cacti user and possibly gain privileges.        View
5862  CVE-2002-1478  Entry  Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.        View
5861  CVE-2002-1477  Entry  graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.        View

Page 19771 of 20943, showing 5 records out of 104715 total, starting on record 98851, ending on 98855

Actions