CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10865 | CVE-2004-2439 | Candidate | The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware. | Assigned (20050820) | None (candidate not yet proposed) | View | |
10864 | CVE-2004-2438 | Candidate | Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field. | Assigned (20050820) | None (candidate not yet proposed) | View | |
10863 | CVE-2004-2437 | Candidate | SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php. | Assigned (20050820) | None (candidate not yet proposed) | View | |
10862 | CVE-2004-2436 | Candidate | Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges. | Assigned (20050820) | None (candidate not yet proposed) | View | |
10861 | CVE-2004-2435 | Candidate | Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts. | Assigned (20050820) | None (candidate not yet proposed) | View |
Page 18771 of 20943, showing 5 records out of 104715 total, starting on record 93851, ending on 93855