CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10627  CVE-2004-2201  Candidate  SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.  Assigned (20050711)  None (candidate not yet proposed)    View
10628  CVE-2004-2202  Candidate  Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server"s underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.  Assigned (20050711)  None (candidate not yet proposed)    View
10629  CVE-2004-2203  Candidate  Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories.  Assigned (20050711)  None (candidate not yet proposed)    View
10630  CVE-2004-2204  Candidate  Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT.  Assigned (20050711)  None (candidate not yet proposed)    View
10631  CVE-2004-2205  Candidate  Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified vectors.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 1795 of 20943, showing 5 records out of 104715 total, starting on record 8971, ending on 8975

Actions