CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8030  CVE-2003-1206  Candidate  Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.  Assigned (20050519)  None (candidate not yet proposed)    View
8029  CVE-2003-1205  Candidate  Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.  Assigned (20050519)  None (candidate not yet proposed)    View
8028  CVE-2003-1204  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.12 BETA and earlier allow remote attackers to execute script on other clients via (1) the link parameter in sectionswindow.php, the directory parameter in (2) gallery.php, (3) navigation.php, or (4) uploadimage.php, the path parameter in (5) view.php, (6) the choice parameter in upload.php, (7) the sitename parameter in mambosimple.php, (8) the type parameter in upload.php, or the id parameter in (9) emailarticle.php, (10) emailfaq.php, or (11) emailnews.php.  Assigned (20050519)  None (candidate not yet proposed)    View
8027  CVE-2003-1203  Candidate  Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.  Assigned (20050519)  None (candidate not yet proposed)    View
8026  CVE-2003-1202  Candidate  The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19338 of 20943, showing 5 records out of 104715 total, starting on record 96686, ending on 96690

Actions