CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10830 | CVE-2004-2404 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2347. Reason: This candidate is a duplicate of CVE-2004-2347. Notes: All CVE users should reference CVE-2004-2347 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Assigned (20050817) | None (candidate not yet proposed) | View | |
10829 | CVE-2004-2403 | Candidate | Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters. | Assigned (20050817) | None (candidate not yet proposed) | View | |
10828 | CVE-2004-2402 | Candidate | Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect. | Assigned (20050817) | None (candidate not yet proposed) | View | |
10827 | CVE-2004-2401 | Candidate | Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." | Assigned (20050817) | None (candidate not yet proposed) | View | |
10826 | CVE-2004-2400 | Candidate | WinFTP Server 1.6 stores username and password credentials in plaintext in the datauser.wfd file, which allows local users to gain access to the credentials. | Assigned (20050817) | None (candidate not yet proposed) | View |
Page 18778 of 20943, showing 5 records out of 104715 total, starting on record 93886, ending on 93890