CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14892  CVE-2005-3688  Candidate  Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page.  Assigned (20051119)  None (candidate not yet proposed)    View
14893  CVE-2005-3689  Candidate  post.php in XMB 1.9.2 allows remote attackers to obtain the installation path via an invalid fid parameter in a newthread action.  Assigned (20051119)  None (candidate not yet proposed)    View
14894  CVE-2005-3690  Candidate  Stack-based buffer overflow in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to execute arbitrary code via a long mailbox name in the (1) select, (2) create, (3) delete, (4) rename, (5) subscribe, or (6) unsubscribe commands.  Assigned (20051119)  None (candidate not yet proposed)    View
14895  CVE-2005-3691  Candidate  Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.  Assigned (20051119)  None (candidate not yet proposed)    View
14896  CVE-2005-3692  Candidate  Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments.  Assigned (20051119)  None (candidate not yet proposed)    View

Page 18706 of 20943, showing 5 records out of 104715 total, starting on record 93526, ending on 93530

Actions