CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7321 | CVE-2003-0494 | Candidate | password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7322 | CVE-2003-0495 | Candidate | Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7323 | CVE-2003-0496 | Candidate | Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7324 | CVE-2003-0497 | Candidate | Cach・Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7325 | CVE-2003-0498 | Candidate | Cach・Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges. | Assigned (20030630) | None (candidate not yet proposed) | View |
Page 714 of 20943, showing 5 records out of 104715 total, starting on record 3566, ending on 3570