CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11898 | CVE-2005-0692 | Candidate | Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript. | Assigned (20050309) | None (candidate not yet proposed) | View | |
11899 | CVE-2005-0693 | Candidate | Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname. | Assigned (20050309) | None (candidate not yet proposed) | View | |
11900 | CVE-2005-0694 | Candidate | Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv. | Assigned (20050309) | None (candidate not yet proposed) | View | |
11901 | CVE-2005-0695 | Candidate | The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner"s e-mail address by providing a portion of the domain name to the "login ID" field. | Assigned (20050309) | None (candidate not yet proposed) | View | |
11902 | CVE-2005-0696 | Candidate | Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5. | Assigned (20050309) | None (candidate not yet proposed) | View |
Page 19668 of 20943, showing 5 records out of 104715 total, starting on record 98336, ending on 98340