CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6329  CVE-2002-1947  Candidate  Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.  Assigned (20050629)  None (candidate not yet proposed)    View
12121  CVE-2005-0915  Candidate  Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.  Assigned (20050329)  None (candidate not yet proposed)    View
2998  CVE-2001-0177  Candidate  WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.  Proposed (20010309)  ACCEPT(1) Frech | NOOP(2) Lawler, Ziese    View
66902  CVE-2013-6955  Candidate  webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.  Assigned (20131204)  None (candidate not yet proposed)    View
35049  CVE-2008-4932  Candidate  webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.  Assigned (20081105)  None (candidate not yet proposed)    View

Page 244 of 20943, showing 5 records out of 104715 total, starting on record 1216, ending on 1220

Actions