CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10950  CVE-2004-2524  Candidate  clogin.php in Benchmark Designs" WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.  Assigned (20051025)  None (candidate not yet proposed)    View
10949  CVE-2004-2523  Candidate  Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.  Assigned (20051025)  None (candidate not yet proposed)    View
10948  CVE-2004-2522  Candidate  Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.  Assigned (20051025)  None (candidate not yet proposed)    View
10947  CVE-2004-2521  Candidate  Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).  Assigned (20051025)  None (candidate not yet proposed)    View
10946  CVE-2004-2520  Candidate  POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.  Assigned (20051025)  None (candidate not yet proposed)    View

Page 18754 of 20943, showing 5 records out of 104715 total, starting on record 93766, ending on 93770

Actions