CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10163  CVE-2004-1735  Candidate  Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.  Assigned (20050226)  None (candidate not yet proposed)    View
10164  CVE-2004-1736  Candidate  Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.  Assigned (20050226)  None (candidate not yet proposed)    View
10165  CVE-2004-1737  Candidate  SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.  Assigned (20050226)  None (candidate not yet proposed)    View
10166  CVE-2004-1738  Candidate  Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.  Assigned (20050226)  None (candidate not yet proposed)    View
10167  CVE-2004-1739  Candidate  Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 1242 of 20943, showing 5 records out of 104715 total, starting on record 6206, ending on 6210

Actions