Skip to main content

Vendor/product archive

open_source_development_network / slashcode CVEs

Beta · best-effort

6 CVEs tagged to open_source_development_network / slashcode0 Critical, 2 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2004-2656

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arb…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1681

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting scri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1748

Published Dec 31, 2002

Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0292

Published May 31, 2002

Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other us…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1535

Published Dec 31, 2001

Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1015

Published Dec 11, 2000

The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly exec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1