CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10338  CVE-2004-1911  Candidate  Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10339  CVE-2004-1912  Candidate  The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.  Assigned (20050504)  None (candidate not yet proposed)    View
10340  CVE-2004-1913  Candidate  Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10341  CVE-2004-1914  Candidate  SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10342  CVE-2004-1915  Candidate  Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1504 of 20943, showing 5 records out of 104715 total, starting on record 7516, ending on 7520

Actions