CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5415  CVE-2002-1027  Candidate  Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> fix typo: "1the"  View
4926  CVE-2002-0535  Candidate  Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.  Modified (20050527)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> ADDREF BID:4561 | URL:http://www.securityfocus.com/bid/4561  View
5458  CVE-2002-1070  Candidate  Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> CONFIRM:http://cvs.sourceforge.net/viewcvs.py/phpwiki/phpwiki/lib/Request.php | This URL is a changelog for Request.php. For revsion 1.17, | dated 20020909, the author says "Prevent from possible XSS attacks" | and includes a sample exploit for the pagename parameter.  View
3427  CVE-2001-0614  Candidate  Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop  Christey> Give the particular nature of the constructed URL, i.e. the | command is specified in the VBEXE parameter.  View
4141  CVE-2001-1337  Candidate  Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(5) Cole, Cox, Foat, Green, Wall  Green> Vendor disputes vulnerability, insufficient follow-up to render an opinion  View

Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575

Actions