CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10225  CVE-2004-1797  Candidate  Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10481  CVE-2004-2055  Candidate  Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10226  CVE-2004-1798  Candidate  RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.  Assigned (20050504)  None (candidate not yet proposed)    View
10482  CVE-2004-2056  Candidate  SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers execute arbitrary SQL statements via the itemid parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10227  CVE-2004-1799  Candidate  PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19469 of 20943, showing 5 records out of 104715 total, starting on record 97341, ending on 97345

Actions