CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9852 | CVE-2004-1424 | Candidate | Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9853 | CVE-2004-1425 | Candidate | Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9854 | CVE-2004-1426 | Candidate | Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9855 | CVE-2004-1427 | Candidate | PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9856 | CVE-2004-1428 | Candidate | ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames. | Assigned (20050212) | None (candidate not yet proposed) | View |
Page 19806 of 20943, showing 5 records out of 104715 total, starting on record 99026, ending on 99030