CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9848  CVE-2004-1420  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9849  CVE-2004-1421  Candidate  Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.  Assigned (20050212)  None (candidate not yet proposed)    View
9850  CVE-2004-1422  Candidate  WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.  Assigned (20050212)  None (candidate not yet proposed)    View
9851  CVE-2004-1423  Candidate  Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.  Assigned (20050212)  None (candidate not yet proposed)    View
9852  CVE-2004-1424  Candidate  Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20050212)  None (candidate not yet proposed)    View

Page 1142 of 20943, showing 5 records out of 104715 total, starting on record 5706, ending on 5710

Actions