CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5843  CVE-2002-1459  Candidate  Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
5844  CVE-2002-1460  Candidate  L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
5845  CVE-2002-1461  Candidate  Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5846  CVE-2002-1462  Candidate  details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5848  CVE-2002-1464  Candidate  Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View

Page 20919 of 20943, showing 5 records out of 104715 total, starting on record 104591, ending on 104595

Actions