CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10225  CVE-2004-1797  Candidate  Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10224  CVE-2004-1796  Candidate  PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.  Assigned (20050504)  None (candidate not yet proposed)    View
10223  CVE-2004-1795  Candidate  Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a "file://" URI.  Assigned (20050504)  None (candidate not yet proposed)    View
10222  CVE-2004-1794  Candidate  Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.  Assigned (20050504)  None (candidate not yet proposed)    View
10221  CVE-2004-1793  Candidate  Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18899 of 20943, showing 5 records out of 104715 total, starting on record 94491, ending on 94495

Actions