CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10640 | CVE-2004-2214 | Candidate | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters. | Assigned (20050717) | None (candidate not yet proposed) | View | |
10639 | CVE-2004-2213 | Candidate | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request. | Assigned (20050717) | None (candidate not yet proposed) | View | |
10638 | CVE-2004-2212 | Candidate | SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10637 | CVE-2004-2211 | Candidate | Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10636 | CVE-2004-2210 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to login.asp, or (6) the email parameter to subscribe/default.asp. | Assigned (20050711) | None (candidate not yet proposed) | View |
Page 18816 of 20943, showing 5 records out of 104715 total, starting on record 94076, ending on 94080