CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10530 | CVE-2004-2104 | Candidate | Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, including the internal IP address, via a direct request to (1) snoop.jsp, (2) SnoopServlet, (3) env.bas, or (4) lcgitest.nlm. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10529 | CVE-2004-2103 | Candidate | Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10528 | CVE-2004-2102 | Candidate | Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10527 | CVE-2004-2101 | Candidate | The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow. | Assigned (20050527) | None (candidate not yet proposed) | View | |
10526 | CVE-2004-2100 | Candidate | GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines). | Assigned (20050527) | None (candidate not yet proposed) | View |
Page 18838 of 20943, showing 5 records out of 104715 total, starting on record 94186, ending on 94190