CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6760  CVE-2002-2378  Candidate  Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.  Assigned (20071031)  None (candidate not yet proposed)    View
6759  CVE-2002-2377  Candidate  Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.  Assigned (20071031)  None (candidate not yet proposed)    View
6758  CVE-2002-2376  Candidate  Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.  Assigned (20071031)  None (candidate not yet proposed)    View
6757  CVE-2002-2375  Candidate  Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information.  Assigned (20071031)  None (candidate not yet proposed)    View
6756  CVE-2002-2374  Candidate  Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."  Assigned (20071031)  None (candidate not yet proposed)    View

Page 19592 of 20943, showing 5 records out of 104715 total, starting on record 97956, ending on 97960

Actions