CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10490 | CVE-2004-2064 | Candidate | Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web script via the (1) Email or (2) Website fields. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10489 | CVE-2004-2063 | Candidate | Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10488 | CVE-2004-2062 | Candidate | SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10487 | CVE-2004-2061 | Candidate | RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10486 | CVE-2004-2060 | Candidate | ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 18846 of 20943, showing 5 records out of 104715 total, starting on record 94226, ending on 94230