CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10338 | CVE-2004-1911 | Candidate | Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10339 | CVE-2004-1912 | Candidate | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10340 | CVE-2004-1913 | Candidate | Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10341 | CVE-2004-1914 | Candidate | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10342 | CVE-2004-1915 | Candidate | Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1504 of 20943, showing 5 records out of 104715 total, starting on record 7516, ending on 7520