CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4271 | CVE-2001-1468 | Candidate | PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4272 | CVE-2001-1469 | Candidate | The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message"s cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4273 | CVE-2001-1470 | Candidate | The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4274 | CVE-2001-1471 | Candidate | prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement. | Assigned (20050421) | None (candidate not yet proposed) | View | |
4275 | CVE-2001-1472 | Candidate | SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter. | Assigned (20050421) | None (candidate not yet proposed) | View |
Page 855 of 20943, showing 5 records out of 104715 total, starting on record 4271, ending on 4275