CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13929  CVE-2005-2723  Candidate  SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie.  Assigned (20050829)  None (candidate not yet proposed)    View
13930  CVE-2005-2724  Candidate  Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.  Assigned (20050829)  None (candidate not yet proposed)    View
13931  CVE-2005-2725  Candidate  The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.  Assigned (20050829)  None (candidate not yet proposed)    View
13932  CVE-2005-2726  Candidate  Directory traversal vulnerability in Home Ftp Server 1.0.7 allows remote authenticated users to read arbitrary files via "C:" (Windows drive letter) sequences in commands such as (1) LIST or (2) RETR.  Assigned (20050829)  None (candidate not yet proposed)    View
13933  CVE-2005-2727  Candidate  Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user"s home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst.  Assigned (20050829)  None (candidate not yet proposed)    View

Page 18943 of 20943, showing 5 records out of 104715 total, starting on record 94711, ending on 94715

Actions