CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14307  CVE-2005-3101  Candidate  The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.  Assigned (20050928)  None (candidate not yet proposed)    View
14308  CVE-2005-3102  Candidate  The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.  Assigned (20050928)  None (candidate not yet proposed)    View
14309  CVE-2005-3103  Candidate  Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.  Assigned (20050928)  None (candidate not yet proposed)    View
14310  CVE-2005-3104  Candidate  mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.  Assigned (20050928)  None (candidate not yet proposed)    View
14267  CVE-2005-3061  Candidate  Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive.  Assigned (20050927)  None (candidate not yet proposed)    View

Page 18870 of 20943, showing 5 records out of 104715 total, starting on record 94346, ending on 94350

Actions