CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12048 | CVE-2005-0842 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter. | Assigned (20050324) | None (candidate not yet proposed) | View | |
12049 | CVE-2005-0843 | Candidate | CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header. | Assigned (20050324) | None (candidate not yet proposed) | View | |
12050 | CVE-2005-0844 | Candidate | Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information. | Assigned (20050324) | None (candidate not yet proposed) | View | |
12051 | CVE-2005-0845 | Candidate | Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter. | Assigned (20050324) | None (candidate not yet proposed) | View | |
12052 | CVE-2005-0846 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field. | Assigned (20050324) | None (candidate not yet proposed) | View |
Page 19619 of 20943, showing 5 records out of 104715 total, starting on record 98091, ending on 98095