CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10081 | CVE-2004-1653 | Candidate | The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10082 | CVE-2004-1654 | Candidate | SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10083 | CVE-2004-1655 | Candidate | Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10084 | CVE-2004-1656 | Candidate | CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10085 | CVE-2004-1657 | Candidate | Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers. | Assigned (20050221) | None (candidate not yet proposed) | View |
Page 1213 of 20943, showing 5 records out of 104715 total, starting on record 6061, ending on 6065