CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9827 | CVE-2004-1399 | Candidate | Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9828 | CVE-2004-1400 | Candidate | The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9829 | CVE-2004-1401 | Candidate | SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9830 | CVE-2004-1402 | Candidate | SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9831 | CVE-2004-1403 | Candidate | PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code. | Assigned (20050212) | None (candidate not yet proposed) | View |
Page 19801 of 20943, showing 5 records out of 104715 total, starting on record 99001, ending on 99005