CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10148  CVE-2004-1720  Candidate  The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.  Assigned (20050226)  None (candidate not yet proposed)    View
10149  CVE-2004-1721  Candidate  The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.  Assigned (20050226)  None (candidate not yet proposed)    View
10150  CVE-2004-1722  Candidate  SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.  Assigned (20050226)  None (candidate not yet proposed)    View
10151  CVE-2004-1723  Candidate  The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.  Assigned (20050226)  None (candidate not yet proposed)    View
10152  CVE-2004-1724  Candidate  The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 1239 of 20943, showing 5 records out of 104715 total, starting on record 6191, ending on 6195

Actions