CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10950 | CVE-2004-2524 | Candidate | clogin.php in Benchmark Designs" WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10949 | CVE-2004-2523 | Candidate | Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10948 | CVE-2004-2522 | Candidate | Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter. | Assigned (20051025) | None (candidate not yet proposed) | View | |
10947 | CVE-2004-2521 | Candidate | Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP). | Assigned (20051025) | None (candidate not yet proposed) | View | |
10946 | CVE-2004-2520 | Candidate | POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands. | Assigned (20051025) | None (candidate not yet proposed) | View |
Page 18754 of 20943, showing 5 records out of 104715 total, starting on record 93766, ending on 93770