CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9574  CVE-2004-1146  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.  Assigned (20041206)  None (candidate not yet proposed)    View
9575  CVE-2004-1147  Candidate  phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.  Assigned (20041206)  None (candidate not yet proposed)    View
9576  CVE-2004-1148  Candidate  phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter.  Assigned (20041206)  None (candidate not yet proposed)    View
9563  CVE-2004-1135  Candidate  Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.  Assigned (20041205)  NOOP(1) Christey  Christey> NOTE: CVE-2004-1135 is for the WS_FTP overflows. It was mistakenly | linked to an issue in w3who (CVE-2004-1133 or CVE-2004-1134)  View
9564  CVE-2004-1136  Candidate  Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.  Assigned (20041205)  None (candidate not yet proposed)    View

Page 19941 of 20943, showing 5 records out of 104715 total, starting on record 99701, ending on 99705

Actions