CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10264  CVE-2004-1837  Candidate  Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.  Assigned (20050504)  None (candidate not yet proposed)    View
7961  CVE-2003-1137  Candidate  Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.  Assigned (20050504)  None (candidate not yet proposed)    View
10265  CVE-2004-1838  Candidate  Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.  Assigned (20050504)  None (candidate not yet proposed)    View
7962  CVE-2003-1138  Candidate  The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).  Assigned (20050504)  None (candidate not yet proposed)    View
10266  CVE-2004-1839  Candidate  MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1476 of 20943, showing 5 records out of 104715 total, starting on record 7376, ending on 7380

Actions