CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7990 | CVE-2003-1166 | Candidate | Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10294 | CVE-2004-1867 | Candidate | Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field. | Assigned (20050504) | None (candidate not yet proposed) | View | |
7991 | CVE-2003-1167 | Candidate | misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10295 | CVE-2004-1868 | Candidate | Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag. | Assigned (20050504) | None (candidate not yet proposed) | View | |
7992 | CVE-2003-1168 | Candidate | HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19420 of 20943, showing 5 records out of 104715 total, starting on record 97096, ending on 97100