CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5843 | CVE-2002-1459 | Candidate | Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5844 | CVE-2002-1460 | Candidate | L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5867 | CVE-2002-1483 | Candidate | db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot). | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
5887 | CVE-2002-1503 | Candidate | Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc. | Proposed (20030317) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
8487 | CVE-2004-0059 | Candidate | Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header. | Modified (20071113) | ACCEPT(2) Baker, Cole | NOOP(3) Armstrong, Cox, Wall | View |
Page 778 of 20943, showing 5 records out of 104715 total, starting on record 3886, ending on 3890