CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14307 | CVE-2005-3101 | Candidate | The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames. | Assigned (20050928) | None (candidate not yet proposed) | View | |
14308 | CVE-2005-3102 | Candidate | The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root. | Assigned (20050928) | None (candidate not yet proposed) | View | |
14309 | CVE-2005-3103 | Candidate | Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries. | Assigned (20050928) | None (candidate not yet proposed) | View | |
14310 | CVE-2005-3104 | Candidate | mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments. | Assigned (20050928) | None (candidate not yet proposed) | View | |
14267 | CVE-2005-3061 | Candidate | Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive. | Assigned (20050927) | None (candidate not yet proposed) | View |
Page 18870 of 20943, showing 5 records out of 104715 total, starting on record 94346, ending on 94350