CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8676 | CVE-2004-0248 | Candidate | Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum. | Modified (20050815) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8677 | CVE-2004-0249 | Candidate | PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie"s PXL variable to reference another userID. | Modified (20050815) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8692 | CVE-2004-0264 | Candidate | palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8693 | CVE-2004-0265 | Candidate | Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8694 | CVE-2004-0266 | Candidate | SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers obtain the administrator password via the c_mid parameter. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View |
Page 665 of 20943, showing 5 records out of 104715 total, starting on record 3321, ending on 3325