CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9852  CVE-2004-1424  Candidate  Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9853  CVE-2004-1425  Candidate  Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9854  CVE-2004-1426  Candidate  Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9855  CVE-2004-1427  Candidate  PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.  Assigned (20050212)  None (candidate not yet proposed)    View
9856  CVE-2004-1428  Candidate  ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.  Assigned (20050212)  None (candidate not yet proposed)    View

Page 19806 of 20943, showing 5 records out of 104715 total, starting on record 99026, ending on 99030

Actions