CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8695 | CVE-2004-0267 | Candidate | The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8697 | CVE-2004-0269 | Candidate | SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8699 | CVE-2004-0271 | Candidate | Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8700 | CVE-2004-0272 | Candidate | SQL injection vulnerability in MaxWebPortal allows remote attackers to inject arbitrary SQL code and gain sensitive information via the SendTo parameter in Personal Messages. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
1732 | CVE-2000-0154 | Candidate | The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack. | Modified (20000403-01) | ACCEPT(1) Cole | NOOP(3) Baker, LeBlanc, Wall | REJECT(3) Christey, Frech, Levy | Christey> DUPE CVE-2000-0224 | Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink | Recommend moving BID reference to CVE-2000-0224. | View |
Page 666 of 20943, showing 5 records out of 104715 total, starting on record 3326, ending on 3330