CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8108  CVE-2003-1284  Candidate  Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe.  Assigned (20051122)  None (candidate not yet proposed)    View
8109  CVE-2003-1285  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3) environ.pl, (4) the query parameter to samples/search.dll, (5) the price parameter to mortgage.pl, (6) the query string in dumpenv.pl, (7) the query string to dumpenv.pl, and (8) the E-Mail field of the guestbook script (book.pl).  Assigned (20051122)  None (candidate not yet proposed)    View
8110  CVE-2003-1286  Candidate  HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server"s administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.  Assigned (20051122)  None (candidate not yet proposed)    View
8111  CVE-2003-1287  Candidate  Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.  Assigned (20051122)  None (candidate not yet proposed)    View
10985  CVE-2004-2559  Candidate  DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks.  Assigned (20051122)  None (candidate not yet proposed)    View

Page 18692 of 20943, showing 5 records out of 104715 total, starting on record 93456, ending on 93460

Actions