CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10434  CVE-2004-2008  Candidate  SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10435  CVE-2004-2009  Candidate  NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.  Assigned (20050504)  None (candidate not yet proposed)    View
10436  CVE-2004-2010  Candidate  PHP remote file inclusion vulnerability in index.php in phpShop 0.7.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the base_dir parameter to reference a URL on a remote web server that contains phpshop.cfg.  Assigned (20050504)  None (candidate not yet proposed)    View
10437  CVE-2004-2011  Candidate  msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI.  Assigned (20050504)  None (candidate not yet proposed)    View
10438  CVE-2004-2012  Candidate  The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19456 of 20943, showing 5 records out of 104715 total, starting on record 97276, ending on 97280

Actions