CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10380  CVE-2004-1954  Candidate  Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10379  CVE-2004-1953  Candidate  phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View
10378  CVE-2004-1952  Candidate  SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.  Assigned (20050504)  None (candidate not yet proposed)    View
10377  CVE-2004-1951  Candidate  xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.  Assigned (20050504)  None (candidate not yet proposed)    View
10376  CVE-2004-1950  Candidate  phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18868 of 20943, showing 5 records out of 104715 total, starting on record 94336, ending on 94340

Actions