CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10096 | CVE-2004-1668 | Candidate | Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10097 | CVE-2004-1669 | Candidate | Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10098 | CVE-2004-1670 | Candidate | Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10099 | CVE-2004-1671 | Candidate | Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html. | Assigned (20050221) | None (candidate not yet proposed) | View | |
10100 | CVE-2004-1672 | Candidate | attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users" attachments by specifying the username and message ID in an HTTP request. | Assigned (20050221) | None (candidate not yet proposed) | View |
Page 1216 of 20943, showing 5 records out of 104715 total, starting on record 6076, ending on 6080