CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10530  CVE-2004-2104  Candidate  Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm.  Assigned (20050527)  None (candidate not yet proposed)    View
10529  CVE-2004-2103  Candidate  Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.  Assigned (20050527)  None (candidate not yet proposed)    View
10528  CVE-2004-2102  Candidate  Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.  Assigned (20050527)  None (candidate not yet proposed)    View
10527  CVE-2004-2101  Candidate  The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.  Assigned (20050527)  None (candidate not yet proposed)    View
10526  CVE-2004-2100  Candidate  GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).  Assigned (20050527)  None (candidate not yet proposed)    View

Page 18838 of 20943, showing 5 records out of 104715 total, starting on record 94186, ending on 94190

Actions