CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9853  CVE-2004-1425  Candidate  Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9854  CVE-2004-1426  Candidate  Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9855  CVE-2004-1427  Candidate  PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.  Assigned (20050212)  None (candidate not yet proposed)    View
9856  CVE-2004-1428  Candidate  ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.  Assigned (20050212)  None (candidate not yet proposed)    View
9857  CVE-2004-1429  Candidate  ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it easier for remote attackers to guess passwords via a brute force attack.  Assigned (20050212)  None (candidate not yet proposed)    View

Page 1143 of 20943, showing 5 records out of 104715 total, starting on record 5711, ending on 5715

Actions