CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8697  CVE-2004-0269  Candidate  SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8699  CVE-2004-0271  Candidate  Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8700  CVE-2004-0272  Candidate  SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8712  CVE-2004-0284  Candidate  Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Christey, Cox | REVIEWING(1) Wall  Christey> MISC:http://www.acrossecurity.com/aspr/ASPR-2004-01-20-1-PUB.txt  View
3118  CVE-2001-0297  Candidate  Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.  Proposed (20010404)  ACCEPT(1) Cole | NOOP(2) Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop  Frech> Dupe of CVE-2001-0186  View

Page 20281 of 20943, showing 5 records out of 104715 total, starting on record 101401, ending on 101405

Actions