CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10031 | CVE-2004-1603 | Candidate | cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10032 | CVE-2004-1604 | Candidate | cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10033 | CVE-2004-1605 | Candidate | SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10034 | CVE-2004-1606 | Candidate | slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie. | Assigned (20050220) | None (candidate not yet proposed) | View | |
10035 | CVE-2004-1607 | Candidate | slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message. | Assigned (20050220) | None (candidate not yet proposed) | View |
Page 19744 of 20943, showing 5 records out of 104715 total, starting on record 98716, ending on 98720