CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9100  CVE-2004-0672  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMinder Web Edition 5.6 allows remote attackers to execute script as other users via (1) script that starts with %00 in the numOfExpressions parameter or (2) the mobjtype parameter.  Assigned (20040712)  None (candidate not yet proposed)    View
9101  CVE-2004-0673  Candidate  Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.  Assigned (20040712)  None (candidate not yet proposed)    View
9102  CVE-2004-0674  Candidate  Enterasys XSR-1800 series Security Routers, when running firmware 7.0.0.0 and using Policy-Based Routing, allow remote attackers to cause a denial of service (crash) via a packet with the IP record route option set.  Assigned (20040712)  None (candidate not yet proposed)    View
9103  CVE-2004-0675  Candidate  Cross-site scripting (XSS) vulnerability in (1) cart32.exe or (2) c32web.exe in Cart32 shopping cart allows remote attackers to execute arbitrary web script via the cart32 parameter to a GetLatestBuilds command.  Assigned (20040712)  None (candidate not yet proposed)    View
9104  CVE-2004-0676  Candidate  Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.  Assigned (20040712)  None (candidate not yet proposed)    View

Page 909 of 20943, showing 5 records out of 104715 total, starting on record 4541, ending on 4545

Actions