CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10148 | CVE-2004-1720 | Candidate | The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10149 | CVE-2004-1721 | Candidate | The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10150 | CVE-2004-1722 | Candidate | SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10151 | CVE-2004-1723 | Candidate | The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message. | Assigned (20050226) | None (candidate not yet proposed) | View | |
10152 | CVE-2004-1724 | Candidate | The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password. | Assigned (20050226) | None (candidate not yet proposed) | View |
Page 1239 of 20943, showing 5 records out of 104715 total, starting on record 6191, ending on 6195