CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5849  CVE-2002-1465  Candidate  SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5594  CVE-2002-1210  Candidate  Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.  Proposed (20030317)  ACCEPT(2) Baker, Green | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Christey  Green> THERE IS AN AMBIGOUS ACKNOWLEDGEMENT TO iDefense"s REPORTING OF THE ISSUE TO THE VENDOR | Christey> Overlap CVE-2002-0456 ?  View
5850  CVE-2002-1466  Candidate  CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.  Proposed (20030317)  NOOP(3) Cole, Cox, Wall    View
5851  CVE-2002-1467  Candidate  Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).  Proposed (20030317)  ACCEPT(3) Baker, Cole, Wall | NOOP(2) Christey, Cox  Christey> REDHAT:RHSA-2003:026  View
5854  CVE-2002-1470  Candidate  SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View

Page 20920 of 20943, showing 5 records out of 104715 total, starting on record 104596, ending on 104600

Actions