CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6046 | CVE-2002-1662 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field during account registration. | Assigned (20050519) | None (candidate not yet proposed) | View | |
6047 | CVE-2002-1663 | Candidate | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value. | Assigned (20050519) | None (candidate not yet proposed) | View | |
2791 | CVE-2000-1224 | Candidate | Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) "..", (2) "%2e..", (3) "%81", (4) "%82", and others. | Assigned (20050519) | None (candidate not yet proposed) | View | |
12853 | CVE-2005-1647 | Candidate | Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords. | Assigned (20050518) | None (candidate not yet proposed) | View | |
12854 | CVE-2005-1648 | Candidate | Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords. | Assigned (20050518) | None (candidate not yet proposed) | View |
Page 19358 of 20943, showing 5 records out of 104715 total, starting on record 96786, ending on 96790