CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8771 | CVE-2004-0343 | Candidate | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php. | Proposed (20040318) | ACCEPT(3) Armstrong, Cole, Stracener | NOOP(3) Balinsky, Cox, Wall | REVIEWING(1) Green | View | |
8772 | CVE-2004-0344 | Candidate | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8773 | CVE-2004-0345 | Candidate | Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name. | Proposed (20040318) | ACCEPT(1) Stracener | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8774 | CVE-2004-0346 | Candidate | Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command. | Proposed (20040318) | ACCEPT(2) Armstrong, Stracener | NOOP(3) Cole, Cox, Wall | View | |
8775 | CVE-2004-0347 | Entry | Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter. | View |
Page 1755 of 20943, showing 5 records out of 104715 total, starting on record 8771, ending on 8775