CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10081  CVE-2004-1653  Candidate  The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.  Assigned (20050221)  None (candidate not yet proposed)    View
10082  CVE-2004-1654  Candidate  SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.  Assigned (20050221)  None (candidate not yet proposed)    View
10083  CVE-2004-1655  Candidate  Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.  Assigned (20050221)  None (candidate not yet proposed)    View
10084  CVE-2004-1656  Candidate  CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.  Assigned (20050221)  None (candidate not yet proposed)    View
10085  CVE-2004-1657  Candidate  Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 1213 of 20943, showing 5 records out of 104715 total, starting on record 6061, ending on 6065

Actions