CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8732  CVE-2004-0304  Candidate  SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8733  CVE-2004-0305  Candidate  Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8738  CVE-2004-0310  Candidate  Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.  Proposed (20040318)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> Despite the description, the specific affected versions are | not actually known. Either they need to be removed or we need | some source that can confirm the affected versions.  View
8739  CVE-2004-0311  Candidate  American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.  Proposed (20040318)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View
8740  CVE-2004-0312  Candidate  Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 5 of 20943, showing 5 records out of 104715 total, starting on record 21, ending on 25

<<first 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions