CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5849  CVE-2002-1465  Candidate  SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5854  CVE-2002-1470  Candidate  SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5882  CVE-2002-1498  Candidate  Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "" characters.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
5883  CVE-2002-1499  Candidate  Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.  Proposed (20030317)  ACCEPT(1) Cole | NOOP(2) Cox, Wall    View
8763  CVE-2004-0335  Candidate  LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Armstrong  Armstrong> If this is a design feature - then it should not be classed as a vulnerability.  View

Page 660 of 20943, showing 5 records out of 104715 total, starting on record 3296, ending on 3300

Actions