CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12691  CVE-2005-1485  Candidate  Golden FTP Server Pro 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.  Assigned (20050511)  None (candidate not yet proposed)    View
12692  CVE-2005-1486  Candidate  Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed. The original researcher is known to be unreliable.  Assigned (20050511)  None (candidate not yet proposed)    View
12693  CVE-2005-1487  Candidate  ** DISPUTED ** Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable.  Assigned (20050511)  None (candidate not yet proposed)    View
12694  CVE-2005-1488  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.html, (2) addressaction.html, (3) the Signature field to settings.html, or (4) the Shared calendars to calendarsettings.html.  Assigned (20050511)  None (candidate not yet proposed)    View
12695  CVE-2005-1489  Candidate  Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.  Assigned (20050511)  None (candidate not yet proposed)    View

Page 19390 of 20943, showing 5 records out of 104715 total, starting on record 96946, ending on 96950

Actions