CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6810 | CVE-2002-2428 | Candidate | webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data. | Assigned (20090206) | None (candidate not yet proposed) | View | |
6809 | CVE-2002-2427 | Candidate | The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603. | Assigned (20090206) | None (candidate not yet proposed) | View | |
6808 | CVE-2002-2426 | Candidate | Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information. | Assigned (20071119) | None (candidate not yet proposed) | View | |
6807 | CVE-2002-2425 | Candidate | Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request. | Assigned (20071101) | None (candidate not yet proposed) | View | |
6806 | CVE-2002-2424 | Candidate | Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag. | Assigned (20071101) | None (candidate not yet proposed) | View |
Page 19582 of 20943, showing 5 records out of 104715 total, starting on record 97906, ending on 97910