CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7995  CVE-2003-1171  Candidate  Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.  Assigned (20050504)  None (candidate not yet proposed)    View
10299  CVE-2004-1872  Candidate  Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.  Assigned (20050504)  None (candidate not yet proposed)    View
7996  CVE-2003-1172  Candidate  Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10300  CVE-2004-1873  Candidate  SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
7997  CVE-2003-1173  Candidate  Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19422 of 20943, showing 5 records out of 104715 total, starting on record 97106, ending on 97110

Actions