CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10940  CVE-2004-2514  Candidate  Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.  Assigned (20051025)  None (candidate not yet proposed)    View
10939  CVE-2004-2513  Candidate  Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.  Assigned (20051025)  None (candidate not yet proposed)    View
10938  CVE-2004-2512  Candidate  CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.  Assigned (20051025)  None (candidate not yet proposed)    View
10937  CVE-2004-2511  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid parameter in news.php; (8) the cid parameter in contents.php; (9) the q parameter in search.php; and (10) the country parameter in register.php.  Assigned (20051025)  None (candidate not yet proposed)    View
10936  CVE-2004-2510  Candidate  Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.  Assigned (20051025)  None (candidate not yet proposed)    View

Page 18756 of 20943, showing 5 records out of 104715 total, starting on record 93776, ending on 93780

Actions