CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8495  CVE-2004-0067  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.  Modified (20090127)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://sourceforge.net/project/showfiles.php?group_id=55456  View
8458  CVE-2004-0030  Candidate  PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> http://phpgedview.sourceforge.net/  View
8471  CVE-2004-0043  Candidate  Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.  Modified (20071113)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(2) Cole, Cox | REVIEWING(1) Wall  Williams> http://lists.netsys.com/pipermail/full-disclosure/2004-January/015355.html | http://www.packetstormsecurity.nl/0401-advisories/yahooIM.txt  View
8502  CVE-2004-0074  Candidate  Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.  Proposed (20040318)  ACCEPT(3) Armstrong, Baker, Williams | NOOP(3) Cole, Cox, Wall  Williams> DSA-405-1  View
8499  CVE-2004-0071  Candidate  Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Williams | NOOP(3) Cole, Cox, Wall  Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0. | http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php | http://php.amnuts.com/forums/viewtopic.php?t=70  View

Page 5 of 20943, showing 5 records out of 104715 total, starting on record 21, ending on 25

<<first 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions