CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10670  CVE-2004-2244  Candidate  The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.  Assigned (20050717)  None (candidate not yet proposed)    View
10669  CVE-2004-2243  Candidate  Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.  Assigned (20050717)  None (candidate not yet proposed)    View
10668  CVE-2004-2242  Candidate  Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.  Assigned (20050717)  None (candidate not yet proposed)    View
10667  CVE-2004-2241  Candidate  Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor"s patch.  Assigned (20050717)  None (candidate not yet proposed)    View
10666  CVE-2004-2240  Candidate  Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 18810 of 20943, showing 5 records out of 104715 total, starting on record 94046, ending on 94050

Actions