CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8715 | CVE-2004-0287 | Candidate | Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow. | Modified (20050518) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> CONFIRM:http://xlightftpd.com/forum/viewtopic.php?t=32 | and http://www.xlightftpd.com/forum/viewtopic.php?t=40 says | that this was fixed in 1.55. | | Also, DELREF BID:9627 - it"s not a clean match. | Instead, ADDREF BID:9668 | View |
8738 | CVE-2004-0310 | Candidate | Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url. | Proposed (20040318) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> Despite the description, the specific affected versions are | not actually known. Either they need to be removed or we need | some source that can confirm the affected versions. | View |
8762 | CVE-2004-0334 | Candidate | InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error. | Modified (20060816) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> According to SecurityTracker.com, the initial advisory | erroneously mentions Axis 1200: | MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html | View |
5120 | CVE-2002-0730 | Candidate | Cross-site scripting vulnerability in guestbook.pl for Philip Chinery"s Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage. | Proposed (20020726) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View | |
5129 | CVE-2002-0739 | Candidate | Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page. | Proposed (20020726) | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | View |
Page 20937 of 20943, showing 5 records out of 104715 total, starting on record 104681, ending on 104685