CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11518  CVE-2005-0312  Candidate  WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.  Assigned (20050210)  None (candidate not yet proposed)    View
11519  CVE-2005-0313  Candidate  Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary directories and files via the IMAP commands (3) CREATE, (4) EXAMINE, (5) SELECT, or (6) DELETE.  Assigned (20050210)  None (candidate not yet proposed)    View
11457  CVE-2005-0251  Candidate  Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.  Assigned (20050209)  None (candidate not yet proposed)    View
11458  CVE-2005-0252  Candidate  SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.  Assigned (20050209)  None (candidate not yet proposed)    View
11459  CVE-2005-0253  Candidate  Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.  Assigned (20050209)  None (candidate not yet proposed)    View

Page 19830 of 20943, showing 5 records out of 104715 total, starting on record 99146, ending on 99150

Actions