CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10990 | CVE-2004-2564 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10989 | CVE-2004-2563 | Candidate | Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10988 | CVE-2004-2562 | Candidate | SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10987 | CVE-2004-2561 | Candidate | Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp. | Assigned (20051122) | None (candidate not yet proposed) | View | |
10986 | CVE-2004-2560 | Candidate | DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi". | Assigned (20051122) | None (candidate not yet proposed) | View |
Page 18746 of 20943, showing 5 records out of 104715 total, starting on record 93726, ending on 93730