CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11689  CVE-2005-0483  Candidate  Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authenticated users to (1) determine the existence of arbitrary files, (2) list files in restricted directories, or (3) read arbitrary files from within ZIP or gzip files, via .. (dot dot) sequences and globbing ("*") characters in a SITE NFO command.  Assigned (20050219)  None (candidate not yet proposed)    View
11690  CVE-2005-0484  Candidate  Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifiers to be inserted into the ProFTPD transfer log.  Assigned (20050219)  None (candidate not yet proposed)    View
11691  CVE-2005-0485  Candidate  Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.  Assigned (20050219)  None (candidate not yet proposed)    View
11692  CVE-2005-0486  Candidate  Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme.  Assigned (20050219)  None (candidate not yet proposed)    View
11693  CVE-2005-0487  Candidate  Cross-site scripting (XSS) vulnerability in index.php for Kayako ESupport 2.3.1, and possibly other versions, allows remote attackers to inject arbitrary HTML and web script via the nav parameter.  Assigned (20050219)  None (candidate not yet proposed)    View

Page 19756 of 20943, showing 5 records out of 104715 total, starting on record 98776, ending on 98780

Actions