CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9932 | CVE-2004-1504 | Candidate | The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9933 | CVE-2004-1505 | Candidate | Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9934 | CVE-2004-1506 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9935 | CVE-2004-1507 | Candidate | CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9936 | CVE-2004-1508 | Candidate | init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter. | Assigned (20050218) | None (candidate not yet proposed) | View |
Page 19761 of 20943, showing 5 records out of 104715 total, starting on record 98801, ending on 98805