CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7960  CVE-2003-1136  Candidate  Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.  Assigned (20050504)  None (candidate not yet proposed)    View
10264  CVE-2004-1837  Candidate  Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.  Assigned (20050504)  None (candidate not yet proposed)    View
7961  CVE-2003-1137  Candidate  Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.  Assigned (20050504)  None (candidate not yet proposed)    View
10265  CVE-2004-1838  Candidate  Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.  Assigned (20050504)  None (candidate not yet proposed)    View
7962  CVE-2003-1138  Candidate  The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19408 of 20943, showing 5 records out of 104715 total, starting on record 97036, ending on 97040

Actions