265891
|
- |
|
icewarp merak
|
web_mail mail_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail a…
|
NVD-CWE-Other
|
CVE-2005-1488
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265892
|
- |
|
icewarp merak
|
web_mail mail_server
|
Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html…
|
NVD-CWE-Other
|
CVE-2005-1489
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265893
|
- |
|
icewarp merak
|
web_mail mail_server
|
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.h…
|
NVD-CWE-Other
|
CVE-2005-1490
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265894
|
- |
|
icewarp merak
|
web_mail mail_server
|
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to …
|
NVD-CWE-Other
|
CVE-2005-1491
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265895
|
- |
|
dead_pirate_software
|
simplecam
|
Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.
|
NVD-CWE-Other
|
CVE-2005-1493
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265896
|
- |
|
megabook
|
megabook
|
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.
|
NVD-CWE-Other
|
CVE-2005-1494
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265897
|
- |
|
oracle
|
application_server oracle10g oracle9i
|
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
|
NVD-CWE-Other
|
CVE-2005-1495
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265898
|
- |
|
oracle
|
application_server oracle10g oracle9i
|
Applying patchset 10.1.0.4 is fixing this issue for Oracle 10g. Oracle 9i is still vulnerable.
|
NVD-CWE-Other
|
CVE-2005-1495
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265899
|
- |
|
oracle
|
application_server oracle10g
|
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
|
NVD-CWE-Other
|
CVE-2005-1496
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265900
|
- |
|
oracle
|
application_server oracle10g
|
Applying patchset 10.1.0.4 is fixing this issue.
|
NVD-CWE-Other
|
CVE-2005-1496
|
2017-07-11 10:32 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|