CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5843  CVE-2002-1459  Candidate  Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
5844  CVE-2002-1460  Candidate  L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
5867  CVE-2002-1483  Candidate  db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
5887  CVE-2002-1503  Candidate  Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc.  Proposed (20030317)  ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall    View
8487  CVE-2004-0059  Candidate  Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.  Modified (20071113)  ACCEPT(2) Baker, Cole | NOOP(3) Armstrong, Cox, Wall    View

Page 778 of 20943, showing 5 records out of 104715 total, starting on record 3886, ending on 3890

Actions