CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9090 | CVE-2004-0662 | Candidate | PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9091 | CVE-2004-0663 | Candidate | Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9092 | CVE-2004-0664 | Candidate | Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9093 | CVE-2004-0665 | Candidate | csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message. | Assigned (20040712) | None (candidate not yet proposed) | View | |
9094 | CVE-2004-0666 | Candidate | Off-by-one error in the POP3_readmsg function in popclient 3.0b6 allows remote attackers to cause a denial of service (application crash) via an e-mail message with a certain line length, which leads to a buffer overflow. | Assigned (20040712) | None (candidate not yet proposed) | View |
Page 907 of 20943, showing 5 records out of 104715 total, starting on record 4531, ending on 4535