CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10990  CVE-2004-2564  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.  Assigned (20051122)  None (candidate not yet proposed)    View
10989  CVE-2004-2563  Candidate  Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.  Assigned (20051122)  None (candidate not yet proposed)    View
10988  CVE-2004-2562  Candidate  SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20051122)  None (candidate not yet proposed)    View
10987  CVE-2004-2561  Candidate  Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.  Assigned (20051122)  None (candidate not yet proposed)    View
10986  CVE-2004-2560  Candidate  DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi".  Assigned (20051122)  None (candidate not yet proposed)    View

Page 18746 of 20943, showing 5 records out of 104715 total, starting on record 93726, ending on 93730

Actions