CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4532  CVE-2002-0138  Candidate  CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command.  Proposed (20020315)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech    View
4608  CVE-2002-0216  Candidate  userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4609  CVE-2002-0217  Candidate  Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4612  CVE-2002-0220  Candidate  phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View
4613  CVE-2002-0221  Candidate  Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.  Proposed (20020502)  ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall    View

Page 20210 of 20943, showing 5 records out of 104715 total, starting on record 101046, ending on 101050

Actions