CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5845 | CVE-2002-1461 | Candidate | Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5844 | CVE-2002-1460 | Candidate | L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5843 | CVE-2002-1459 | Candidate | Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5842 | CVE-2002-1458 | Candidate | Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5841 | CVE-2002-1457 | Candidate | SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View |
Page 19775 of 20943, showing 5 records out of 104715 total, starting on record 98871, ending on 98875