CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5320 | CVE-2002-0932 | Candidate | SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog. | Proposed (20020830) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
5321 | CVE-2002-0933 | Candidate | Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks. | Proposed (20020830) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
5322 | CVE-2002-0934 | Candidate | Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file. | Proposed (20020830) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
5324 | CVE-2002-0936 | Candidate | The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | Modified (20070509) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
5325 | CVE-2002-0937 | Candidate | The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | Proposed (20020830) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View |
Page 823 of 20943, showing 5 records out of 104715 total, starting on record 4111, ending on 4115