CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4344 | CVE-2001-1544 | Candidate | Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6392 | CVE-2002-2010 | Candidate | Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4345 | CVE-2001-1545 | Candidate | Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies enabled, which allows remote attackers to obtain session IDs and hijack sessions via HTTP referrer fields or sniffing. | Assigned (20050714) | None (candidate not yet proposed) | View | |
6393 | CVE-2002-2011 | Candidate | Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter. | Assigned (20050714) | None (candidate not yet proposed) | View | |
4346 | CVE-2001-1546 | Candidate | Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 19132 of 20943, showing 5 records out of 104715 total, starting on record 95656, ending on 95660