CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6730  CVE-2002-2348  Candidate  Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter.  Assigned (20071029)  None (candidate not yet proposed)    View
6729  CVE-2002-2347  Candidate  Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.  Assigned (20071029)  None (candidate not yet proposed)    View
6728  CVE-2002-2346  Candidate  phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.  Assigned (20071029)  None (candidate not yet proposed)    View
6727  CVE-2002-2345  Candidate  Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.  Assigned (20071029)  None (candidate not yet proposed)    View
6726  CVE-2002-2344  Candidate  Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target"s email address.  Assigned (20071029)  None (candidate not yet proposed)    View

Page 19598 of 20943, showing 5 records out of 104715 total, starting on record 97986, ending on 97990

Actions