CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8494 | CVE-2004-0066 | Candidate | phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall | Williams> http://sourceforge.net/project/showfiles.php?group_id=55456 | View |
8495 | CVE-2004-0067 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1. | Modified (20090127) | ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall | Williams> http://sourceforge.net/project/showfiles.php?group_id=55456 | View |
8445 | CVE-2004-0017 | Candidate | Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations. | Modified (20071113) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall | Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier. | http://phpgroupware.org/downloads | View |
8457 | CVE-2004-0029 | Candidate | Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges. | Modified (20071113) | ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams | Williams> insufficient data. | View |
8465 | CVE-2004-0037 | Candidate | FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages. | Modified (20071113) | ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams | Williams> insufficient data. | View |
Page 20940 of 20943, showing 5 records out of 104715 total, starting on record 104696, ending on 104700