CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8732 | CVE-2004-0304 | Candidate | SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8733 | CVE-2004-0305 | Candidate | Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8738 | CVE-2004-0310 | Candidate | Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url. | Proposed (20040318) | NOOP(5) Armstrong, Christey, Cole, Cox, Wall | Christey> Despite the description, the specific affected versions are | not actually known. Either they need to be removed or we need | some source that can confirm the affected versions. | View |
8739 | CVE-2004-0311 | Candidate | American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access. | Proposed (20040318) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall | View | |
8740 | CVE-2004-0312 | Candidate | Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 5 of 20943, showing 5 records out of 104715 total, starting on record 21, ending on 25