CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8695  CVE-2004-0267  Candidate  The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8697  CVE-2004-0269  Candidate  SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8699  CVE-2004-0271  Candidate  Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.  Modified (20050518)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8700  CVE-2004-0272  Candidate  SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
1732  CVE-2000-0154  Candidate  The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.  Modified (20000403-01)  ACCEPT(1) Cole | NOOP(3) Baker, LeBlanc, Wall | REJECT(3) Christey, Frech, Levy  Christey> DUPE CVE-2000-0224 | Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink | Recommend moving BID reference to CVE-2000-0224.  View

Page 666 of 20943, showing 5 records out of 104715 total, starting on record 3326, ending on 3330

Actions