CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11463 | CVE-2005-0257 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20050209) | None (candidate not yet proposed) | View | |
11464 | CVE-2005-0258 | Candidate | Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (unlink) arbitrary files via "/../" sequences in the avatarselect parameter. | Assigned (20050209) | None (candidate not yet proposed) | View | |
11465 | CVE-2005-0259 | Candidate | phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file. | Assigned (20050209) | None (candidate not yet proposed) | View | |
11520 | CVE-2005-0314 | Candidate | Cross-site scripting (XSS) vulnerability in user.php in Magic Winmail Server 4.0 Build 1112 allows remote attackers to inject arbitrary web script or HTML via the personal information fields. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11521 | CVE-2005-0315 | Candidate | The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 1114 of 20943, showing 5 records out of 104715 total, starting on record 5566, ending on 5570