CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10995 | CVE-2004-2569 | Candidate | ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack on the ipmenu.log temporary file. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10994 | CVE-2004-2568 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10993 | CVE-2004-2567 | Candidate | Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10992 | CVE-2004-2566 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10991 | CVE-2004-2565 | Candidate | Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a ".." (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp. | Assigned (20051122) | None (candidate not yet proposed) | View |
Page 18745 of 20943, showing 5 records out of 104715 total, starting on record 93721, ending on 93725