CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9110  CVE-2004-0682  Candidate  comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to change the prices of items by directly modifying them in the URL.  Assigned (20040712)  None (candidate not yet proposed)    View
9109  CVE-2004-0681  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffice_message.asp, (3) comersus_supportError.asp, or (4) comersus_message.asp in Comersus Cart 5.09 allow remote attackers to execute web script as other users via the message parameter.  Assigned (20040712)  None (candidate not yet proposed)    View
9108  CVE-2004-0680  Candidate  Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.  Assigned (20040712)  None (candidate not yet proposed)    View
9107  CVE-2004-0679  Candidate  The IP cloaking feature (cloak.c) in UnrealIRCd 3.2, and possibly other versions, uses a weak hashing scheme to hide IP addresses, which could allow remote attackers to use brute force methods to gain other user"s IP addresses.  Assigned (20040712)  None (candidate not yet proposed)    View
9106  CVE-2004-0678  Candidate  Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.  Assigned (20040712)  None (candidate not yet proposed)    View

Page 19122 of 20943, showing 5 records out of 104715 total, starting on record 95606, ending on 95610

Actions