CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37198  CVE-2008-7081  Candidate  userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20090824)  None (candidate not yet proposed)    View
11524  CVE-2005-0318  Candidate  useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users" account information via a modified user parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
14626  CVE-2005-3420  Candidate  usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.  Assigned (20051101)  None (candidate not yet proposed)    View
20554  CVE-2006-4450  Candidate  usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.  Assigned (20060829)  None (candidate not yet proposed)    View
34284  CVE-2008-4167  Candidate  useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.  Assigned (20080922)  None (candidate not yet proposed)    View

Page 587 of 20943, showing 5 records out of 104715 total, starting on record 2931, ending on 2935

Actions