CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10466  CVE-2004-2040  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary web script or HTML via the (1) LAN_407 parameter to clock_menu.php, (2) "email article to a friend" field, (3) "submit news" field, or (4) avmsg parameter to usersettings.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10211  CVE-2004-1783  Candidate  Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).  Assigned (20050504)  None (candidate not yet proposed)    View
10467  CVE-2004-2041  Candidate  PHP remote file inclusion vulnerability in secure_img_render.php in e107 0.615 allows remote attackers to execute arbitrary PHP code by modifying the p parameter to reference a URL on a remote web server that contains the code.  Assigned (20050504)  None (candidate not yet proposed)    View
10212  CVE-2004-1784  Candidate  Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.  Assigned (20050504)  None (candidate not yet proposed)    View
10468  CVE-2004-2042  Candidate  Multiple SQL injection vulnerabilities in e107 0.615 allow remote attackers to inject arbitrary SQL code and gain sensitive information via (1) content parameter to content.php, (2) content_id parameter to content.php, or (3) list parameter to news.php.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1531 of 20943, showing 5 records out of 104715 total, starting on record 7651, ending on 7655

Actions