CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
37198 | CVE-2008-7081 | Candidate | userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20090824) | None (candidate not yet proposed) | View | |
11524 | CVE-2005-0318 | Candidate | useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users" account information via a modified user parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
14626 | CVE-2005-3420 | Candidate | usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement. | Assigned (20051101) | None (candidate not yet proposed) | View | |
20554 | CVE-2006-4450 | Candidate | usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request. | Assigned (20060829) | None (candidate not yet proposed) | View | |
34284 | CVE-2008-4167 | Candidate | useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account. | Assigned (20080922) | None (candidate not yet proposed) | View |
Page 587 of 20943, showing 5 records out of 104715 total, starting on record 2931, ending on 2935