CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9574 | CVE-2004-1146 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9575 | CVE-2004-1147 | Candidate | phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9576 | CVE-2004-1148 | Candidate | phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | Assigned (20041206) | None (candidate not yet proposed) | View | |
9563 | CVE-2004-1135 | Candidate | Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands. | Assigned (20041205) | NOOP(1) Christey | Christey> NOTE: CVE-2004-1135 is for the WS_FTP overflows. It was mistakenly | linked to an issue in w3who (CVE-2004-1133 or CVE-2004-1134) | View |
9564 | CVE-2004-1136 | Candidate | Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands. | Assigned (20041205) | None (candidate not yet proposed) | View |
Page 19941 of 20943, showing 5 records out of 104715 total, starting on record 99701, ending on 99705