CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4532 | CVE-2002-0138 | Candidate | CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command. | Proposed (20020315) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech | View | |
4608 | CVE-2002-0216 | Candidate | userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
4609 | CVE-2002-0217 | Candidate | Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
4612 | CVE-2002-0220 | Candidate | phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
4613 | CVE-2002-0221 | Candidate | Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View |
Page 20210 of 20943, showing 5 records out of 104715 total, starting on record 101046, ending on 101050