The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user’s email account.
The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.
The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user’s system by encoding it within an email message or news post.
Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.