CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10550 | CVE-2004-2124 | Candidate | The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10549 | CVE-2004-2123 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10548 | CVE-2004-2122 | Candidate | Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10547 | CVE-2004-2121 | Candidate | Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "..") sequences, in the URL. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10546 | CVE-2004-2120 | Candidate | Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version. | Assigned (20050527) | None (candidate not yet proposed) | View |
Page 18834 of 20943, showing 5 records out of 104715 total, starting on record 94166, ending on 94170