CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8495  CVE-2004-0067  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.  Modified (20090127)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8494  CVE-2004-0066  Candidate  phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8493  CVE-2004-0065  Candidate  Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.  Modified (20071113)  ACCEPT(4) Armstrong, Baker, Cole, Williams | NOOP(2) Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8492  CVE-2004-0064  Candidate  The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.  Modified (20071113)  ACCEPT(2) Baker, Cole | NOOP(3) Armstrong, Cox, Wall    View
8491  CVE-2004-0063  Entry  The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.        View

Page 19245 of 20943, showing 5 records out of 104715 total, starting on record 96221, ending on 96225

Actions