CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4926  CVE-2002-0535  Candidate  Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.  Modified (20050527)  ACCEPT(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> ADDREF BID:4561 | URL:http://www.securityfocus.com/bid/4561  View
4927  CVE-2002-0536  Entry  PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.        View
4928  CVE-2002-0537  Candidate  The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View
4929  CVE-2002-0538  Entry  FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server"s "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability.        View
4930  CVE-2002-0539  Entry  Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.        View

Page 986 of 20943, showing 5 records out of 104715 total, starting on record 4926, ending on 4930

Actions