CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10161  CVE-2004-1733  Candidate  Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.  Assigned (20050226)  None (candidate not yet proposed)    View
10162  CVE-2004-1734  Candidate  PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.  Assigned (20050226)  None (candidate not yet proposed)    View
10163  CVE-2004-1735  Candidate  Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.  Assigned (20050226)  None (candidate not yet proposed)    View
10164  CVE-2004-1736  Candidate  Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.  Assigned (20050226)  None (candidate not yet proposed)    View
10165  CVE-2004-1737  Candidate  SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 19702 of 20943, showing 5 records out of 104715 total, starting on record 98506, ending on 98510

Actions