CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6943  CVE-2003-0114  Candidate  The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.  Assigned (20030226)  None (candidate not yet proposed)    View
6944  CVE-2003-0115  Candidate  Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.  Assigned (20030226)  None (candidate not yet proposed)    View
6945  CVE-2003-0116  Candidate  Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."  Assigned (20030226)  None (candidate not yet proposed)    View
6946  CVE-2003-0117  Candidate  Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.  Assigned (20030226)  None (candidate not yet proposed)    View
6947  CVE-2003-0118  Candidate  SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.  Assigned (20030226)  None (candidate not yet proposed)    View

Page 20306 of 20943, showing 5 records out of 104715 total, starting on record 101526, ending on 101530

Actions