CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8494  CVE-2004-0066  Candidate  phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8497  CVE-2004-0069  Candidate  Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Cox, Williams | REVIEWING(1) Wall  Williams> insufficient data. | Armstrong> Add reference: http://www.securiteam.com/exploits/5TP0C1FBPS.html  View
8499  CVE-2004-0071  Candidate  Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Williams | NOOP(3) Cole, Cox, Wall  Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0. | http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php | http://php.amnuts.com/forums/viewtopic.php?t=70  View
8500  CVE-2004-0072  Candidate  Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded .. (backslash .., "%5c%2e%2e") sequences in an HTTP request.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | NOOP(4) Cole, Cox, Wall, Williams  Williams> insufficient data.  View
6973  CVE-2003-0144  Candidate  Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.  Modified (20071113)  ACCEPT(4) Armstrong, Cole, Green, Jones | NOOP(2) Christey, Cox  Christey> DEBIAN:DSA-267 | URL:http://www.debian.org/security/2003/dsa-267 | Christey> DEBIAN:DSA-275 | URL:http://www.debian.org/security/2003/dsa-275 | Christey> DEBIAN:DSA-267 | URL:http://www.debian.org/security/2003/dsa-267 | Christey> SGI:20030406-02-P | Christey> MANDRAKE:MDKSA-2003:059 | URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2003:059  View

Page 461 of 20943, showing 5 records out of 104715 total, starting on record 2301, ending on 2305

Actions