CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8755  CVE-2004-0327  Candidate  Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(4) Armstrong, Balinsky, Cox, Wall    View
8754  CVE-2004-0326  Candidate  Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.  Proposed (20040318)  ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall    View
8753  CVE-2004-0325  Candidate  TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8752  CVE-2004-0324  Candidate  Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View
8751  CVE-2004-0323  Candidate  Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.  Modified (20051128)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View

Page 19193 of 20943, showing 5 records out of 104715 total, starting on record 95961, ending on 95965

Actions