CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9937 | CVE-2004-1509 | Candidate | validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9938 | CVE-2004-1510 | Candidate | WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9939 | CVE-2004-1511 | Candidate | Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9940 | CVE-2004-1512 | Candidate | Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page. | Assigned (20050218) | None (candidate not yet proposed) | View | |
9941 | CVE-2004-1513 | Candidate | 04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries. | Assigned (20050218) | None (candidate not yet proposed) | View |
Page 19762 of 20943, showing 5 records out of 104715 total, starting on record 98806, ending on 98810