CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4911 | CVE-2002-0520 | Candidate | Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag. | Proposed (20020611) | ACCEPT(3) Baker, Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall | View | |
4912 | CVE-2002-0521 | Candidate | Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp. | Proposed (20020611) | ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4913 | CVE-2002-0522 | Candidate | ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie. | Proposed (20020611) | ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4914 | CVE-2002-0523 | Candidate | ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie. | Proposed (20020611) | ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View | |
4915 | CVE-2002-0524 | Candidate | ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message. | Proposed (20020611) | ACCEPT(4) Armstrong, Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall | View |
Page 983 of 20943, showing 5 records out of 104715 total, starting on record 4911, ending on 4915