CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10630 | CVE-2004-2204 | Candidate | Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10629 | CVE-2004-2203 | Candidate | Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10628 | CVE-2004-2202 | Candidate | Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server"s underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10627 | CVE-2004-2201 | Candidate | SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form. | Assigned (20050711) | None (candidate not yet proposed) | View | |
10626 | CVE-2004-2200 | Candidate | Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text. | Assigned (20050711) | None (candidate not yet proposed) | View |
Page 18818 of 20943, showing 5 records out of 104715 total, starting on record 94086, ending on 94090