CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8730  CVE-2004-0302  Candidate  Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8729  CVE-2004-0301  Candidate  Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.  Modified (20051204)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8728  CVE-2004-0300  Candidate  SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.  Modified (20051204)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8727  CVE-2004-0299  Candidate  Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8726  CVE-2004-0298  Candidate  CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 19198 of 20943, showing 5 records out of 104715 total, starting on record 95986, ending on 95990

Actions