CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10747 | CVE-2004-2321 | Candidate | BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10748 | CVE-2004-2322 | Candidate | SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrary SQL queries, as demonstrated using the ANN_id parameter to the announce module. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10749 | CVE-2004-2323 | Candidate | DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10750 | CVE-2004-2324 | Candidate | SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx. | Assigned (20050816) | None (candidate not yet proposed) | View | |
10751 | CVE-2004-2325 | Candidate | Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML. | Assigned (20050816) | None (candidate not yet proposed) | View |
Page 19016 of 20943, showing 5 records out of 104715 total, starting on record 95076, ending on 95080