CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10490  CVE-2004-2064  Candidate  Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields.  Assigned (20050504)  None (candidate not yet proposed)    View
10489  CVE-2004-2063  Candidate  Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10488  CVE-2004-2062  Candidate  SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10487  CVE-2004-2061  Candidate  RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10486  CVE-2004-2060  Candidate  ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18846 of 20943, showing 5 records out of 104715 total, starting on record 94226, ending on 94230

Actions