CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10435  CVE-2004-2009  Candidate  NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View
10434  CVE-2004-2008  Candidate  SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10433  CVE-2004-2007  Candidate  Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.  Assigned (20050504)  None (candidate not yet proposed)    View
10432  CVE-2004-2006  Candidate  Trend Micro OfficeScan 3.0 - 6.0 has default permissions of "Everyone Full Control" on the installation directory and registry keys, which allows local users to disable virus protection.  Assigned (20050504)  None (candidate not yet proposed)    View
10431  CVE-2004-2005  Candidate  Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18857 of 20943, showing 5 records out of 104715 total, starting on record 94281, ending on 94285

Actions