NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
74285 | CVE-2003-1213 | The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
74284 | CVE-2003-1212 | MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
74283 | CVE-2003-1211 | Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
74282 | CVE-2003-1210 | Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
74281 | CVE-2003-1209 | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 16102 of 17672, showing 5 records out of 88360 total, starting on record 80506, ending on 80510