CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7318 | CVE-2003-0491 | Candidate | The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7319 | CVE-2003-0492 | Candidate | Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7320 | CVE-2003-0493 | Candidate | Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7321 | CVE-2003-0494 | Candidate | password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7322 | CVE-2003-0495 | Candidate | Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item. | Assigned (20030627) | None (candidate not yet proposed) | View |
Page 20234 of 20943, showing 5 records out of 104715 total, starting on record 101166, ending on 101170