CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8755 | CVE-2004-0327 | Candidate | Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(4) Armstrong, Balinsky, Cox, Wall | View | |
8754 | CVE-2004-0326 | Candidate | Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request. | Proposed (20040318) | ACCEPT(2) Armstrong, Cole | NOOP(3) Balinsky, Cox, Wall | View | |
8753 | CVE-2004-0325 | Candidate | TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty". | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8752 | CVE-2004-0324 | Candidate | Confirm 0.62 and earlier could allow remote attackers to execute arbitrary code via an e-mail header that contains shell metacharacters such as ", `, |, ;, or $. | Proposed (20040318) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View | |
8751 | CVE-2004-0323 | Candidate | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta. | Modified (20051128) | ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall | View |
Page 19193 of 20943, showing 5 records out of 104715 total, starting on record 95961, ending on 95965