CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8494  CVE-2004-0066  Candidate  phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8495  CVE-2004-0067  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.  Modified (20090127)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8445  CVE-2004-0017  Candidate  Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Williams | NOOP(2) Cox, Wall  Williams> i believe this affects phpGroupWare 0.9.14.006 and earlier, and phpGroupWare 0.9.16RC1 and earlier. | http://phpgroupware.org/downloads  View
8457  CVE-2004-0029  Candidate  Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View
8465  CVE-2004-0037  Candidate  FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View

Page 20940 of 20943, showing 5 records out of 104715 total, starting on record 104696, ending on 104700

Actions