CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10450 | CVE-2004-2024 | Candidate | The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10451 | CVE-2004-2025 | Candidate | SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10452 | CVE-2004-2026 | Candidate | Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10453 | CVE-2004-2027 | Candidate | Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10454 | CVE-2004-2028 | Candidate | Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or HTML via the referer parameter to log.php. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 1527 of 20943, showing 5 records out of 104715 total, starting on record 7631, ending on 7635