CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4911  CVE-2002-0520  Candidate  Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.  Proposed (20020611)  ACCEPT(3) Baker, Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall    View
4912  CVE-2002-0521  Candidate  Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp.  Proposed (20020611)  ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4913  CVE-2002-0522  Candidate  ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.  Proposed (20020611)  ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4914  CVE-2002-0523  Candidate  ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.  Proposed (20020611)  ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
4915  CVE-2002-0524  Candidate  ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message.  Proposed (20020611)  ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View

Page 983 of 20943, showing 5 records out of 104715 total, starting on record 4911, ending on 4915

Actions