CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10158  CVE-2004-1730  Candidate  Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php.  Assigned (20050226)  None (candidate not yet proposed)    View
10159  CVE-2004-1731  Candidate  signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.  Assigned (20050226)  None (candidate not yet proposed)    View
10160  CVE-2004-1732  Candidate  SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.  Assigned (20050226)  None (candidate not yet proposed)    View
10161  CVE-2004-1733  Candidate  Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.  Assigned (20050226)  None (candidate not yet proposed)    View
10162  CVE-2004-1734  Candidate  PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 1241 of 20943, showing 5 records out of 104715 total, starting on record 6201, ending on 6205

Actions