CVE List

Id CVE No. Status Description Phase Votes Comments Actions
16035  CVE-2005-4831  Candidate  viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting (XSS) and other attacks, as demonstrated using (1) "text/html", or (2) "image/jpeg" with an image that is rendered as HTML by Internet Explorer, a different vulnerability than CVE-2004-1062. NOTE: it was later reported that 0.9.4 is also affected.  Assigned (20070303)  None (candidate not yet proposed)    View
11445  CVE-2005-0239  Candidate  viewcert.php in the S/MIME plugin 0.4 and 0.5 for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the cert parameter.  Assigned (20050207)  None (candidate not yet proposed)    View
12033  CVE-2005-0827  Candidate  Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive information via an invalid parameter to the convertorderbytrans function, which reveals the path in a PHP error message.  Assigned (20050322)  None (candidate not yet proposed)    View
22568  CVE-2006-6464  Candidate  viewcart in Midicart accepts negative numbers in the Qty (quantity) field, which allows remote attackers to obtain a smaller total price for a shopping cart.  Assigned (20061211)  None (candidate not yet proposed)    View
10102  CVE-2004-1674  Candidate  viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter.  Assigned (20050221)  None (candidate not yet proposed)    View

Page 549 of 20943, showing 5 records out of 104715 total, starting on record 2741, ending on 2745

Actions