CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7110 | CVE-2003-0282 | Candidate | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence. | Assigned (20030512) | None (candidate not yet proposed) | View | |
7111 | CVE-2003-0283 | Candidate | Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author"s name, or (3) author"s e-mail. | Assigned (20030512) | None (candidate not yet proposed) | View | |
7112 | CVE-2003-0284 | Candidate | Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus. | Assigned (20030513) | None (candidate not yet proposed) | View | |
7113 | CVE-2003-0285 | Candidate | IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail. | Assigned (20030513) | None (candidate not yet proposed) | View | |
7114 | CVE-2003-0286 | Candidate | SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable. | Assigned (20030513) | None (candidate not yet proposed) | View |
Page 671 of 20943, showing 5 records out of 104715 total, starting on record 3351, ending on 3355