CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8731 | CVE-2004-0303 | Candidate | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8732 | CVE-2004-0304 | Candidate | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8733 | CVE-2004-0305 | Candidate | Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8734 | CVE-2004-0306 | Entry | Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories. | View | |||
8735 | CVE-2004-0307 | Entry | Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead. | View |
Page 1747 of 20943, showing 5 records out of 104715 total, starting on record 8731, ending on 8735