CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10265  CVE-2004-1838  Candidate  Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10264  CVE-2004-1837  Candidate  Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.  Assigned (20050504)  None (candidate not yet proposed)    View
10263  CVE-2004-1836  Candidate  SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.  Assigned (20050504)  None (candidate not yet proposed)    View
10262  CVE-2004-1835  Candidate  Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10261  CVE-2004-1834  Candidate  mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18891 of 20943, showing 5 records out of 104715 total, starting on record 94451, ending on 94455

Actions