CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5849 | CVE-2002-1465 | Candidate | SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5594 | CVE-2002-1210 | Candidate | Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context. | Proposed (20030317) | ACCEPT(2) Baker, Green | NOOP(3) Cole, Cox, Wall | REVIEWING(1) Christey | Green> THERE IS AN AMBIGOUS ACKNOWLEDGEMENT TO iDefense"s REPORTING OF THE ISSUE TO THE VENDOR | Christey> Overlap CVE-2002-0456 ? | View |
5850 | CVE-2002-1466 | Candidate | CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable. | Proposed (20030317) | NOOP(3) Cole, Cox, Wall | View | |
5851 | CVE-2002-1467 | Candidate | Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file). | Proposed (20030317) | ACCEPT(3) Baker, Cole, Wall | NOOP(2) Christey, Cox | Christey> REDHAT:RHSA-2003:026 | View |
5854 | CVE-2002-1470 | Candidate | SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View |
Page 20920 of 20943, showing 5 records out of 104715 total, starting on record 104596, ending on 104600