CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10008 | CVE-2004-1580 | Candidate | SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10009 | CVE-2004-1581 | Candidate | BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10010 | CVE-2004-1582 | Candidate | PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10011 | CVE-2004-1583 | Candidate | Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10012 | CVE-2004-1584 | Candidate | CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter. | Assigned (20050220) | None (candidate not yet proposed) | View |
Page 1196 of 20943, showing 5 records out of 104715 total, starting on record 5976, ending on 5980