CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12863  CVE-2005-1657  Candidate  Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml.  Assigned (20050518)  None (candidate not yet proposed)    View
12864  CVE-2005-1658  Candidate  Directory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL with a "..." (triple dot).  Assigned (20050518)  None (candidate not yet proposed)    View
12865  CVE-2005-1659  Candidate  Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..." (triple dot) followed by an onmouseover event.  Assigned (20050518)  None (candidate not yet proposed)    View
12866  CVE-2005-1660  Candidate  HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.  Assigned (20050518)  None (candidate not yet proposed)    View
12867  CVE-2005-1661  Candidate  Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow.  Assigned (20050518)  None (candidate not yet proposed)    View

Page 1584 of 20943, showing 5 records out of 104715 total, starting on record 7916, ending on 7920

Actions