
CVE-2007-3821
https://notcve.org/view.php?id=CVE-2007-3821
17 Jul 2007 — Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actions as arbitrary users via unspecified vectors. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Webcit anterior a 7.11 permite a atacantes remotos modificar configuraciones y realizar otras acciones como un usuario de su elección a través de vectores no especificados. • http://osvdb.org/38181 •

CVE-2007-3822 – Citadel WebCit 7.02/7.10 - 'showuser?who' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2007-3822
17 Jul 2007 — Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Webcit anterior a 7.11 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) who en showuser; y... • https://www.exploit-db.com/exploits/30312 •

CVE-2004-1192 – Citadel/UX 6.27 - Format String
https://notcve.org/view.php?id=CVE-2004-1192
15 Dec 2004 — Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server. • https://www.exploit-db.com/exploits/681 •

CVE-2004-1705 – Citadel/UX - Remote Denial of Service (PoC)
https://notcve.org/view.php?id=CVE-2004-1705
30 Jul 2004 — Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username. • https://www.exploit-db.com/exploits/370 •

CVE-2004-1933
https://notcve.org/view.php?id=CVE-2004-1933
12 Apr 2004 — Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages. • http://marc.info/?l=bugtraq&m=108180024428804&w=2 •

CVE-2002-0432
https://notcve.org/view.php?id=CVE-2002-0432
11 Jun 2002 — Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks such as a long HELO command to the SMTP server. • http://online.securityfocus.com/archive/1/260934 •