CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6329 | CVE-2002-1947 | Candidate | Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session. | Assigned (20050629) | None (candidate not yet proposed) | View | |
12121 | CVE-2005-0915 | Candidate | Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php. | Assigned (20050329) | None (candidate not yet proposed) | View | |
2998 | CVE-2001-0177 | Candidate | WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone. | Proposed (20010309) | ACCEPT(1) Frech | NOOP(2) Lawler, Ziese | View | |
66902 | CVE-2013-6955 | Candidate | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header. | Assigned (20131204) | None (candidate not yet proposed) | View | |
35049 | CVE-2008-4932 | Candidate | webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root. | Assigned (20081105) | None (candidate not yet proposed) | View |
Page 244 of 20943, showing 5 records out of 104715 total, starting on record 1216, ending on 1220