CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7413  CVE-2003-0586  Candidate  Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.  Assigned (20030717)  None (candidate not yet proposed)    View
7414  CVE-2003-0587  Candidate  Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.  Assigned (20030717)  None (candidate not yet proposed)    View
7415  CVE-2003-0588  Candidate  admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View
7416  CVE-2003-0589  Candidate  admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.  Assigned (20030717)  None (candidate not yet proposed)    View
7417  CVE-2003-0590  Candidate  Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.  Assigned (20030717)  None (candidate not yet proposed)    View

Page 732 of 20943, showing 5 records out of 104715 total, starting on record 3656, ending on 3660

Actions