CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8729  CVE-2004-0301  Candidate  Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.  Modified (20051204)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8730  CVE-2004-0302  Candidate  Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8731  CVE-2004-0303  Candidate  OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8732  CVE-2004-0304  Candidate  SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8733  CVE-2004-0305  Candidate  Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 17 of 20943, showing 5 records out of 104715 total, starting on record 81, ending on 85

Actions