CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7990  CVE-2003-1166  Candidate  Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10294  CVE-2004-1867  Candidate  Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.  Assigned (20050504)  None (candidate not yet proposed)    View
7991  CVE-2003-1167  Candidate  misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.  Assigned (20050504)  None (candidate not yet proposed)    View
10295  CVE-2004-1868  Candidate  Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.  Assigned (20050504)  None (candidate not yet proposed)    View
7992  CVE-2003-1168  Candidate  HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19420 of 20943, showing 5 records out of 104715 total, starting on record 97096, ending on 97100

Actions