CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10627 | CVE-2004-2201 | Candidate | SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10628 | CVE-2004-2202 | Candidate | Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server"s underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10629 | CVE-2004-2203 | Candidate | Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10630 | CVE-2004-2204 | Candidate | Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10631 | CVE-2004-2205 | Candidate | Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified vectors. | Assigned (20050711) | None (candidate not yet proposed) | View |
Page 1795 of 20943, showing 5 records out of 104715 total, starting on record 8971, ending on 8975