CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5415 | CVE-2002-1027 | Candidate | Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> fix typo: "1the" | View |
4926 | CVE-2002-0535 | Candidate | Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title. | Modified (20050527) | ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> ADDREF BID:4561 | URL:http://www.securityfocus.com/bid/4561 | View |
5458 | CVE-2002-1070 | Candidate | Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter. | Proposed (20020830) | ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> CONFIRM:http://cvs.sourceforge.net/viewcvs.py/phpwiki/phpwiki/lib/Request.php | This URL is a changelog for Request.php. For revsion 1.17, | dated 20020909, the author says "Prevent from possible XSS attacks" | and includes a sample exploit for the pagename parameter. | View |
3427 | CVE-2001-0614 | Candidate | Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL. | Proposed (20010727) | ACCEPT(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop | Christey> Give the particular nature of the constructed URL, i.e. the | command is specified in the VBEXE parameter. | View |
4141 | CVE-2001-1337 | Candidate | Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request. | Proposed (20020502) | ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall | Green> Vendor disputes vulnerability, insufficient follow-up to render an opinion | View |
Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575