CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11518 | CVE-2005-0312 | Candidate | WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11519 | CVE-2005-0313 | Candidate | Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE. | Assigned (20050210) | None (candidate not yet proposed) | View | |
11457 | CVE-2005-0251 | Candidate | Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter. | Assigned (20050209) | None (candidate not yet proposed) | View | |
11458 | CVE-2005-0252 | Candidate | SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password. | Assigned (20050209) | None (candidate not yet proposed) | View | |
11459 | CVE-2005-0253 | Candidate | Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter. | Assigned (20050209) | None (candidate not yet proposed) | View |
Page 19830 of 20943, showing 5 records out of 104715 total, starting on record 99146, ending on 99150