CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8095 | CVE-2003-1271 | Candidate | Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8094 | CVE-2003-1270 | Candidate | AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8093 | CVE-2003-1269 | Candidate | AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8092 | CVE-2003-1268 | Candidate | Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8091 | CVE-2003-1267 | Candidate | GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1. | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 19325 of 20943, showing 5 records out of 104715 total, starting on record 96621, ending on 96625