CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8703 | CVE-2004-0275 | Candidate | SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8724 | CVE-2004-0296 | Candidate | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection. | Modified (20050707) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey | Christey> The description is incomplete. Wonder what it was about the | original researcher that was important enough to note? | Christey> What was I saying in the desc about the original researcher??? | View |
5929 | CVE-2002-1545 | Candidate | CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. | Proposed (20030317) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey | Christey> This seems like a rediscovery of CVE-2001-0934. | View |
8683 | CVE-2004-0255 | Candidate | Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Christey | Christey> MISC:http://www.xlightftpd.com/forum/viewtopic.php?t=40 | In the above URL, the vendor says that only one of 3 bugs | reported in February 2004 were an "actual server bug," and the other 2 | "traced back into windows" dll and they won"t happen if windows | service pack is installed. | | The "actual server bug" is CVE-2004-0287. The demonstration | for *this* issue shows that the application breaks in comctl32.dll. | So, this candidate may be erroneous, and an interesting side effect of | another bug that"s not related to xlight at all. | | Thus, this candidate may need to be REJECTED. | View |
8519 | CVE-2004-0091 | Candidate | ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called "reg_site", nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft." | Modified (20051208) | NOOP(4) Armstrong, Cole, Cox, Wall | REVIEWING(1) Green | View |
Page 20931 of 20943, showing 5 records out of 104715 total, starting on record 104651, ending on 104655