CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12426  CVE-2005-1220  Candidate  Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes.  Assigned (20050422)  None (candidate not yet proposed)    View
12427  CVE-2005-1221  Candidate  SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field.  Assigned (20050422)  None (candidate not yet proposed)    View
12428  CVE-2005-1222  Candidate  cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.  Assigned (20050422)  None (candidate not yet proposed)    View
12429  CVE-2005-1223  Candidate  Multiple SQL injection vulnerabilities in Ocean12 Calendar manager 1.01 allow remote attackers to execute arbitrary SQL commands via the Admin_id field.  Assigned (20050422)  None (candidate not yet proposed)    View
12430  CVE-2005-1224  Candidate  Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp or detail.asp, (4) the iData parameter to detail.asp or result.asp, the (5) POL_ID, (6) POL_PARENT, (7) POL_CATEGORY, (8) CHA_NAME, or (9) CHA_ID parameters to inc_vote.asp, or the (10) tfm_order or (11) tfm_orderby parameters to toppages.asp, a different set of vulnerabilities than CVE-2005-1236.  Assigned (20050422)  None (candidate not yet proposed)    View

Page 1423 of 20943, showing 5 records out of 104715 total, starting on record 7111, ending on 7115

Actions