CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12694  CVE-2005-1488  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.html, (2) addressaction.html, (3) the Signature field to settings.html, or (4) the Shared calendars to calendarsettings.html.  Assigned (20050511)  None (candidate not yet proposed)    View
12695  CVE-2005-1489  Candidate  Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.  Assigned (20050511)  None (candidate not yet proposed)    View
12696  CVE-2005-1490  Candidate  Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.  Assigned (20050511)  None (candidate not yet proposed)    View
12697  CVE-2005-1491  Candidate  Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.  Assigned (20050511)  None (candidate not yet proposed)    View
12698  CVE-2005-1492  Candidate  Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.  Assigned (20050511)  None (candidate not yet proposed)    View

Page 1550 of 20943, showing 5 records out of 104715 total, starting on record 7746, ending on 7750

Actions