CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10233  CVE-2004-1806  Candidate  SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10489  CVE-2004-2063  Candidate  Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10234  CVE-2004-1807  Candidate  Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10490  CVE-2004-2064  Candidate  Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.  Assigned (20050504)  None (candidate not yet proposed)    View
10235  CVE-2004-1808  Candidate  Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 1540 of 20943, showing 5 records out of 104715 total, starting on record 7696, ending on 7700

Actions