CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8765  CVE-2004-0337  Candidate  Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall    View
8764  CVE-2004-0336  Entry  LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.        View
8763  CVE-2004-0335  Candidate  LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.  Proposed (20040318)  ACCEPT(1) Cole | NOOP(2) Cox, Wall | REJECT(1) Armstrong  Armstrong> If this is a design feature - then it should not be classed as a vulnerability.  View
8762  CVE-2004-0334  Candidate  InnoMedia VideoPhone allows remote attackers to bypass Basic Authorization via an HTTP request to (1) videophone_admindetail.asp, (2) videophone_syscfg.asp, (3) videophone_upgrade.asp, or (4) videophone_sysctrl.asp that contains a trailing / (slash). NOTE: the original report mentioned AXIS 2100 Network Camera, but this was likely a cut-and-paste error.  Modified (20060816)  NOOP(5) Armstrong, Christey, Cole, Cox, Wall  Christey> According to SecurityTracker.com, the initial advisory | erroneously mentions Axis 1200: | MISC:http://securitytracker.com/alerts/2004/Mar/1009522.html  View
8761  CVE-2004-0333  Candidate  Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.  Modified (20050808)  ACCEPT(4) Armstrong, Baker, Cole, Wall | NOOP(2) Christey, Cox  Christey> Consider this Gentoo reference: | BUGTRAQ:20040328 [ GLSA 200403-05 ] UUDeview MIME Buffer Overflow | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=108057738810928&w=2 | | May need to rephrase this description to emphasize UUDeview | over WinZip.  View

Page 19191 of 20943, showing 5 records out of 104715 total, starting on record 95951, ending on 95955

Actions