CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8703  CVE-2004-0275  Candidate  SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8724  CVE-2004-0296  Candidate  TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.  Modified (20050707)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> The description is incomplete. Wonder what it was about the | original researcher that was important enough to note? | Christey> What was I saying in the desc about the original researcher???  View
5929  CVE-2002-1545  Candidate  CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.  Proposed (20030317)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> This seems like a rediscovery of CVE-2001-0934.  View
8683  CVE-2004-0255  Candidate  Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey  Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40 | In the above URL, the vendor says that only one of 3 bugs | reported in February 2004 were an "actual server bug," and the other 2 | "traced back into windows" dll and they won"t happen if windows | service pack is installed. | | The "actual server bug" is CVE-2004-0287. The demonstration | for *this* issue shows that the application breaks in comctl32.dll. | So, this candidate may be erroneous, and an interesting side effect of | another bug that"s not related to xlight at all. | | Thus, this candidate may need to be REJECTED.  View
8519  CVE-2004-0091  Candidate  ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called "reg_site", nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."  Modified (20051208)  NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green    View

Page 20931 of 20943, showing 5 records out of 104715 total, starting on record 104651, ending on 104655

Actions