CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9630  CVE-2004-1202  Candidate  Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter.  Assigned (20041214)  None (candidate not yet proposed)    View
9631  CVE-2004-1203  Candidate  parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server"s installation path.  Assigned (20041214)  None (candidate not yet proposed)    View
9632  CVE-2004-1204  Candidate  FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.  Assigned (20041214)  None (candidate not yet proposed)    View
9633  CVE-2004-1205  Candidate  codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message.  Assigned (20041214)  None (candidate not yet proposed)    View
9634  CVE-2004-1206  Candidate  Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.  Assigned (20041214)  None (candidate not yet proposed)    View

Page 19924 of 20943, showing 5 records out of 104715 total, starting on record 99616, ending on 99620

Actions