CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10008  CVE-2004-1580  Candidate  SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.  Assigned (20050220)  None (candidate not yet proposed)    View
10009  CVE-2004-1581  Candidate  BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.  Assigned (20050220)  None (candidate not yet proposed)    View
10010  CVE-2004-1582  Candidate  PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.  Assigned (20050220)  None (candidate not yet proposed)    View
10011  CVE-2004-1583  Candidate  Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.  Assigned (20050220)  None (candidate not yet proposed)    View
10012  CVE-2004-1584  Candidate  CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 1196 of 20943, showing 5 records out of 104715 total, starting on record 5976, ending on 5980

Actions