CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7325  CVE-2003-0498  Candidate  Cach・Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.  Assigned (20030630)  None (candidate not yet proposed)    View
7326  CVE-2003-0499  Candidate  Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.  Assigned (20030630)  None (candidate not yet proposed)    View
7327  CVE-2003-0500  Candidate  SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.  Assigned (20030630)  None (candidate not yet proposed)    View
7301  CVE-2003-0474  Candidate  Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.  Assigned (20030627)  None (candidate not yet proposed)    View
7302  CVE-2003-0475  Candidate  Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.  Assigned (20030627)  None (candidate not yet proposed)    View

Page 20230 of 20943, showing 5 records out of 104715 total, starting on record 101146, ending on 101150

Actions