CVE List

Id CVE No. Status Description Phase Votes Comments Actions
32595  CVE-2008-2478  Candidate  ** DISPUTED ** scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I"m unable to reproduce such an issue on multiple servers running different versions of cPanel."  Assigned (20080528)  None (candidate not yet proposed)    View
21484  CVE-2006-5380  Candidate  ** DISPUTED ** Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value.  Assigned (20061017)  None (candidate not yet proposed)    View
12959  CVE-2005-1753  Candidate  ** DISPUTED ** ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users" e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products."  Assigned (20050526)  None (candidate not yet proposed)    View
23117  CVE-2006-7013  Candidate  ** DISPUTED ** QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.  Assigned (20070214)  None (candidate not yet proposed)    View
22275  CVE-2006-6171  Candidate  ** DISPUTED ** ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability.  Assigned (20061130)  None (candidate not yet proposed)    View

Page 20884 of 20943, showing 5 records out of 104715 total, starting on record 104416, ending on 104420

Actions