CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11950  CVE-2005-0744  Candidate  The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication cookie from the browser.  Assigned (20050313)  None (candidate not yet proposed)    View
11951  CVE-2005-0745  Candidate  UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.  Assigned (20050313)  None (candidate not yet proposed)    View
11952  CVE-2005-0746  Candidate  The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.  Assigned (20050313)  None (candidate not yet proposed)    View
11953  CVE-2005-0747  Candidate  ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.asp.  Assigned (20050313)  None (candidate not yet proposed)    View
11954  CVE-2005-0748  Candidate  PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.  Assigned (20050313)  None (candidate not yet proposed)    View

Page 19648 of 20943, showing 5 records out of 104715 total, starting on record 98236, ending on 98240

Actions