CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10071  CVE-2004-1643  Candidate  WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.  Assigned (20050221)  None (candidate not yet proposed)    View
10072  CVE-2004-1644  Candidate  Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.  Assigned (20050221)  None (candidate not yet proposed)    View
10073  CVE-2004-1645  Candidate  Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.  Assigned (20050221)  None (candidate not yet proposed)    View
10074  CVE-2004-1646  Candidate  Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.  Assigned (20050221)  None (candidate not yet proposed)    View
10075  CVE-2004-1647  Candidate  SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 1211 of 20943, showing 5 records out of 104715 total, starting on record 6051, ending on 6055

Actions