NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80431  CVE-2002-1478  Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.    10  High  2017-01-05  2008-09-05  View
80432  CVE-2002-1479  Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users modify databases as the Cacti user and possibly gain privileges.    4.6  Medium  2017-01-05  2008-09-05  View
80433  CVE-2002-1480  Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.    6.8  Medium  2017-01-05  2008-09-05  View
80434  CVE-2002-1481  savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.    7.5  High  2017-01-05  2008-09-05  View
80435  CVE-2002-1482  SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.    10  High  2017-01-05  2008-09-05  View

Page 1153 of 17672, showing 5 records out of 88360 total, starting on record 5761, ending on 5765

Actions