CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10311 | CVE-2004-1884 | Candidate | Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access. | Assigned (20050504) | None (candidate not yet proposed) | View | |
8008 | CVE-2003-1184 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs." | Assigned (20050504) | None (candidate not yet proposed) | View | |
10312 | CVE-2004-1885 | Candidate | Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe. | Assigned (20050504) | None (candidate not yet proposed) | View | |
8009 | CVE-2003-1185 | Candidate | Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10313 | CVE-2004-1886 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1848. Reason: This candidate is a duplicate of CVE-2004-1848. Notes: All CVE users should reference CVE-2004-1848 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19427 of 20943, showing 5 records out of 104715 total, starting on record 97131, ending on 97135