CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10535  CVE-2004-2109  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL.  Assigned (20050527)  None (candidate not yet proposed)    View
10534  CVE-2004-2108  Candidate  Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.  Assigned (20050527)  None (candidate not yet proposed)    View
10533  CVE-2004-2107  Candidate  Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.  Assigned (20050527)  None (candidate not yet proposed)    View
10532  CVE-2004-2106  Candidate  Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to list directories via a direct request to (1) /com/, (2) /com/novell/, (3) /com/novell/webaccess, or (4) /ns-icons/.  Assigned (20050527)  None (candidate not yet proposed)    View
10531  CVE-2004-2105  Candidate  The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt files via a full pathname in the error parameter.  Assigned (20050527)  None (candidate not yet proposed)    View

Page 18837 of 20943, showing 5 records out of 104715 total, starting on record 94181, ending on 94185

Actions