CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8730 | CVE-2004-0302 | Candidate | Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8731 | CVE-2004-0303 | Candidate | OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8732 | CVE-2004-0304 | Candidate | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8733 | CVE-2004-0305 | Candidate | Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8740 | CVE-2004-0312 | Candidate | Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 20924 of 20943, showing 5 records out of 104715 total, starting on record 104616, ending on 104620