CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7325 | CVE-2003-0498 | Candidate | Cach・Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7326 | CVE-2003-0499 | Candidate | Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7327 | CVE-2003-0500 | Candidate | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7301 | CVE-2003-0474 | Candidate | Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7302 | CVE-2003-0475 | Candidate | Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474. | Assigned (20030627) | None (candidate not yet proposed) | View |
Page 20230 of 20943, showing 5 records out of 104715 total, starting on record 101146, ending on 101150