CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10869  CVE-2004-2443  Candidate  Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.  Assigned (20050820)  None (candidate not yet proposed)    View
10870  CVE-2004-2444  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter.  Assigned (20050820)  None (candidate not yet proposed)    View
10871  CVE-2004-2445  Candidate  Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter.  Assigned (20050820)  None (candidate not yet proposed)    View
10872  CVE-2004-2446  Candidate  Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors.  Assigned (20050820)  None (candidate not yet proposed)    View
10873  CVE-2004-2447  Candidate  Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6) list.tagz.  Assigned (20050820)  None (candidate not yet proposed)    View

Page 18966 of 20943, showing 5 records out of 104715 total, starting on record 94826, ending on 94830

Actions