CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11898  CVE-2005-0692  Candidate  Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.  Assigned (20050309)  None (candidate not yet proposed)    View
11899  CVE-2005-0693  Candidate  Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.  Assigned (20050309)  None (candidate not yet proposed)    View
11900  CVE-2005-0694  Candidate  Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.  Assigned (20050309)  None (candidate not yet proposed)    View
11901  CVE-2005-0695  Candidate  The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner"s e-mail address by providing a portion of the domain name to the "login ID" field.  Assigned (20050309)  None (candidate not yet proposed)    View
11902  CVE-2005-0696  Candidate  Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.  Assigned (20050309)  None (candidate not yet proposed)    View

Page 19668 of 20943, showing 5 records out of 104715 total, starting on record 98336, ending on 98340

Actions