CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11130  CVE-2004-2704  Candidate  Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.  Assigned (20071006)  None (candidate not yet proposed)    View
11129  CVE-2004-2703  Candidate  Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".  Assigned (20071006)  None (candidate not yet proposed)    View
11128  CVE-2004-2702  Candidate  Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.  Assigned (20071006)  None (candidate not yet proposed)    View
11127  CVE-2004-2701  Candidate  Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.  Assigned (20071006)  None (candidate not yet proposed)    View
11126  CVE-2004-2700  Candidate  Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.  Assigned (20071006)  None (candidate not yet proposed)    View

Page 18718 of 20943, showing 5 records out of 104715 total, starting on record 93586, ending on 93590

Actions