CVE List
| Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
|---|---|---|---|---|---|---|---|
| 9977 | CVE-2004-1549 | Candidate | The conference menu in ActivePost Standard 3.1 sends passwords of password-protected rooms in cleartext, which could allow remote attackers to gain sensitive information by sniffing the network connection. | Assigned (20050220) | None (candidate not yet proposed) | View | |
| 9978 | CVE-2004-1550 | Candidate | Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on. | Assigned (20050220) | None (candidate not yet proposed) | View | |
| 9979 | CVE-2004-1551 | Candidate | Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter. | Assigned (20050220) | None (candidate not yet proposed) | View | |
| 9980 | CVE-2004-1552 | Candidate | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. | Assigned (20050220) | None (candidate not yet proposed) | View | |
| 9981 | CVE-2004-1553 | Candidate | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action. | Assigned (20050220) | None (candidate not yet proposed) | View |
Page 1209 of 20943, showing 5 records out of 104715 total, starting on record 6041, ending on 6045