Show filters
123 Total Results
Displaying 101-110 of 123
Sort by:
Attacker Value
Unknown

CVE-2005-4266

Disclosure Date: December 15, 2005 (last updated February 22, 2025)
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
0
Attacker Value
Unknown

CVE-2005-4209

Disclosure Date: December 13, 2005 (last updated February 22, 2025)
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown

CVE-2005-3189

Disclosure Date: November 18, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.
0
Attacker Value
Unknown

CVE-2005-3465

Disclosure Date: November 02, 2005 (last updated February 22, 2025)
Unspecified vulnerability in JDEdwards HTML Server in Oracle EnterpriseOne 8.94 OneWorld XE up to 8.95_B1, 8.94_Q1, and SP23_K1 has unknown impact and attack vectors, as identified by Oracle Vuln# JDE01.
0
Attacker Value
Unknown

CVE-2005-3435

Disclosure Date: November 02, 2005 (last updated February 22, 2025)
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.
Attacker Value
Unknown

CVE-2005-3434

Disclosure Date: November 02, 2005 (last updated February 22, 2025)
Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges.
0
Attacker Value
Unknown

CVE-2005-2639

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
Buffer overflow in Chris Moneymaker's World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.
0
Attacker Value
Unknown

CVE-2005-1161

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.
0
Attacker Value
Unknown

CVE-2005-1328

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp.
0
Attacker Value
Unknown

CVE-2005-1329

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.
0