CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10630  CVE-2004-2204  Candidate  Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT.  Assigned (20050711)  None (candidate not yet proposed)    View
10629  CVE-2004-2203  Candidate  Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories.  Assigned (20050711)  None (candidate not yet proposed)    View
10628  CVE-2004-2202  Candidate  Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server"s underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.  Assigned (20050711)  None (candidate not yet proposed)    View
10627  CVE-2004-2201  Candidate  SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.  Assigned (20050711)  None (candidate not yet proposed)    View
10626  CVE-2004-2200  Candidate  Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 18818 of 20943, showing 5 records out of 104715 total, starting on record 94086, ending on 94090

Actions