CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10311  CVE-2004-1884  Candidate  Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.  Assigned (20050504)  None (candidate not yet proposed)    View
8008  CVE-2003-1184  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."  Assigned (20050504)  None (candidate not yet proposed)    View
10312  CVE-2004-1885  Candidate  Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.  Assigned (20050504)  None (candidate not yet proposed)    View
8009  CVE-2003-1185  Candidate  Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10313  CVE-2004-1886  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1848. Reason: This candidate is a duplicate of CVE-2004-1848. Notes: All CVE users should reference CVE-2004-1848 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19427 of 20943, showing 5 records out of 104715 total, starting on record 97131, ending on 97135

Actions