CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4271  CVE-2001-1468  Candidate  PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.  Assigned (20050421)  None (candidate not yet proposed)    View
4272  CVE-2001-1469  Candidate  The RC4 stream cipher as used by SSH1 allows remote attackers to modify messages without detection by XORing the original message"s cyclic redundancy check (CRC) with the CRC of a mask consisting of all the bits of the original message that were modified.  Assigned (20050421)  None (candidate not yet proposed)    View
4273  CVE-2001-1470  Candidate  The IDEA cipher as implemented by SSH1 does not protect the final block of a message against modification, which allows remote attackers to modify the block without detection by changing its cyclic redundancy check (CRC) to match the modifications to the message.  Assigned (20050421)  None (candidate not yet proposed)    View
4274  CVE-2001-1471  Candidate  prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.  Assigned (20050421)  None (candidate not yet proposed)    View
4275  CVE-2001-1472  Candidate  SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.  Assigned (20050421)  None (candidate not yet proposed)    View

Page 855 of 20943, showing 5 records out of 104715 total, starting on record 4271, ending on 4275

Actions