CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9932  CVE-2004-1504  Candidate  The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.  Assigned (20050218)  None (candidate not yet proposed)    View
9933  CVE-2004-1505  Candidate  Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.  Assigned (20050218)  None (candidate not yet proposed)    View
9934  CVE-2004-1506  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.  Assigned (20050218)  None (candidate not yet proposed)    View
9935  CVE-2004-1507  Candidate  CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.  Assigned (20050218)  None (candidate not yet proposed)    View
9936  CVE-2004-1508  Candidate  init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.  Assigned (20050218)  None (candidate not yet proposed)    View

Page 19761 of 20943, showing 5 records out of 104715 total, starting on record 98801, ending on 98805

Actions