CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10625  CVE-2004-2199  Candidate  Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text.  Assigned (20050711)  None (candidate not yet proposed)    View
10626  CVE-2004-2200  Candidate  Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.  Assigned (20050711)  None (candidate not yet proposed)    View
10627  CVE-2004-2201  Candidate  SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.  Assigned (20050711)  None (candidate not yet proposed)    View
10628  CVE-2004-2202  Candidate  Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server"s underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.  Assigned (20050711)  None (candidate not yet proposed)    View
10629  CVE-2004-2203  Candidate  Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 19156 of 20943, showing 5 records out of 104715 total, starting on record 95776, ending on 95780

Actions