CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12569  CVE-2005-1363  Candidate  Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to productsByCategory.asp or (8) intProdID parameter to product.asp.  Assigned (20050428)  None (candidate not yet proposed)    View
12570  CVE-2005-1364  Candidate  Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.  Assigned (20050428)  None (candidate not yet proposed)    View
12571  CVE-2005-1365  Candidate  Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.  Assigned (20050502)  None (candidate not yet proposed)    View
12572  CVE-2005-1366  Candidate  Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL.  Assigned (20050502)  None (candidate not yet proposed)    View
12573  CVE-2005-1367  Candidate  Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.  Assigned (20050502)  None (candidate not yet proposed)    View

Page 1452 of 20943, showing 5 records out of 104715 total, starting on record 7256, ending on 7260

Actions