CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10865  CVE-2004-2439  Candidate  The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.  Assigned (20050820)  None (candidate not yet proposed)    View
10864  CVE-2004-2438  Candidate  Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.  Assigned (20050820)  None (candidate not yet proposed)    View
10863  CVE-2004-2437  Candidate  SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.  Assigned (20050820)  None (candidate not yet proposed)    View
10862  CVE-2004-2436  Candidate  Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.  Assigned (20050820)  None (candidate not yet proposed)    View
10861  CVE-2004-2435  Candidate  Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.  Assigned (20050820)  None (candidate not yet proposed)    View

Page 18771 of 20943, showing 5 records out of 104715 total, starting on record 93851, ending on 93855

Actions