CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8729 | CVE-2004-0301 | Candidate | Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter. | Modified (20051204) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8730 | CVE-2004-0302 | Candidate | Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8731 | CVE-2004-0303 | Candidate | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8732 | CVE-2004-0304 | Candidate | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8733 | CVE-2004-0305 | Candidate | Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 17 of 20943, showing 5 records out of 104715 total, starting on record 81, ending on 85