CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11522 | CVE-2005-0316 | Candidate | WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11523 | CVE-2005-0317 | Candidate | Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11524 | CVE-2005-0318 | Candidate | useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users" account information via a modified user parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11525 | CVE-2005-0319 | Candidate | Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11526 | CVE-2005-0320 | Candidate | Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add.html, or the (3) note, (4) title, and (5) location fields to calendar.html. | Assigned (20050210) | None (candidate not yet proposed) | View |
Page 19813 of 20943, showing 5 records out of 104715 total, starting on record 99061, ending on 99065