CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7321  CVE-2003-0494  Candidate  password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.  Assigned (20030627)  None (candidate not yet proposed)    View
7322  CVE-2003-0495  Candidate  Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.  Assigned (20030627)  None (candidate not yet proposed)    View
7323  CVE-2003-0496  Candidate  Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.  Assigned (20030630)  None (candidate not yet proposed)    View
7324  CVE-2003-0497  Candidate  Cach・Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.  Assigned (20030630)  None (candidate not yet proposed)    View
7325  CVE-2003-0498  Candidate  Cach・Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.  Assigned (20030630)  None (candidate not yet proposed)    View

Page 714 of 20943, showing 5 records out of 104715 total, starting on record 3566, ending on 3570

Actions