CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10033  CVE-2004-1605  Candidate  SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator.  Assigned (20050220)  None (candidate not yet proposed)    View
10034  CVE-2004-1606  Candidate  slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.  Assigned (20050220)  None (candidate not yet proposed)    View
10035  CVE-2004-1607  Candidate  slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.  Assigned (20050220)  None (candidate not yet proposed)    View
10036  CVE-2004-1608  Candidate  SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.  Assigned (20050220)  None (candidate not yet proposed)    View
10037  CVE-2004-1609  Candidate  SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 1201 of 20943, showing 5 records out of 104715 total, starting on record 6001, ending on 6005

Actions