CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10058  CVE-2004-1630  Candidate  Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.  Assigned (20050220)  None (candidate not yet proposed)    View
10059  CVE-2004-1631  Candidate  Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.  Assigned (20050220)  None (candidate not yet proposed)    View
10060  CVE-2004-1632  Candidate  Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.  Assigned (20050220)  None (candidate not yet proposed)    View
10061  CVE-2004-1633  Candidate  process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.  Assigned (20050220)  None (candidate not yet proposed)    View
10062  CVE-2004-1634  Candidate  show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 1206 of 20943, showing 5 records out of 104715 total, starting on record 6026, ending on 6030

Actions