CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11525  CVE-2005-0319  Candidate  Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks.  Assigned (20050210)  None (candidate not yet proposed)    View
11524  CVE-2005-0318  Candidate  useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users" account information via a modified user parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11523  CVE-2005-0317  Candidate  Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.  Assigned (20050210)  None (candidate not yet proposed)    View
11522  CVE-2005-0316  Candidate  WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.  Assigned (20050210)  None (candidate not yet proposed)    View
11521  CVE-2005-0315  Candidate  The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 18639 of 20943, showing 5 records out of 104715 total, starting on record 93191, ending on 93195

Actions