CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5425  CVE-2002-1037  Candidate  Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
5426  CVE-2002-1038  Candidate  Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.  Proposed (20020830)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
5428  CVE-2002-1040  Candidate  Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.  Proposed (20020830)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:aix-dsfweb-scripts-insecure(10390)  View
5429  CVE-2002-1041  Candidate  Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.  Proposed (20020830)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:aix-smit-panels-insecure(10393)  View
5430  CVE-2002-1042  Candidate  Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via .. (dot-dot backslash) sequences in the NS-query-pat parameter.  Proposed (20020830)  ACCEPT(1) Frech | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Wall    View

Page 51 of 20943, showing 5 records out of 104715 total, starting on record 251, ending on 255

Actions