CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5813 | CVE-2002-1429 | Candidate | Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5054 | CVE-2002-0664 | Candidate | The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5826 | CVE-2002-1442 | Candidate | The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window"s location to the toolbar"s configuration URL, which bypasses the origin verification check. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5843 | CVE-2002-1459 | Candidate | Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5844 | CVE-2002-1460 | Candidate | L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View |
Page 20168 of 20943, showing 5 records out of 104715 total, starting on record 100836, ending on 100840