CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8730  CVE-2004-0302  Candidate  Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8731  CVE-2004-0303  Candidate  OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8732  CVE-2004-0304  Candidate  SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8733  CVE-2004-0305  Candidate  Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8740  CVE-2004-0312  Candidate  Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 20924 of 20943, showing 5 records out of 104715 total, starting on record 104616, ending on 104620

Actions