CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10995  CVE-2004-2569  Candidate  ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack on the ipmenu.log temporary file.  Assigned (20051122)  None (candidate not yet proposed)    View
10994  CVE-2004-2568  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.  Assigned (20051122)  None (candidate not yet proposed)    View
10993  CVE-2004-2567  Candidate  Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.  Assigned (20051122)  None (candidate not yet proposed)    View
10992  CVE-2004-2566  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.  Assigned (20051122)  None (candidate not yet proposed)    View
10991  CVE-2004-2565  Candidate  Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a ".." (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.  Assigned (20051122)  None (candidate not yet proposed)    View

Page 18745 of 20943, showing 5 records out of 104715 total, starting on record 93721, ending on 93725

Actions