CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12689  CVE-2005-1483  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter.  Assigned (20050511)  None (candidate not yet proposed)    View
12690  CVE-2005-1484  Candidate  Directory traversal vulnerability in Golden FTP server pro 2.52 allows remote attackers to read arbitrary files via a ".." (backward slash dot dot) with a leading """ (double quote) in the GET command.  Assigned (20050511)  None (candidate not yet proposed)    View
12691  CVE-2005-1485  Candidate  Golden FTP Server Pro 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.  Assigned (20050511)  None (candidate not yet proposed)    View
12692  CVE-2005-1486  Candidate  Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed. The original researcher is known to be unreliable.  Assigned (20050511)  None (candidate not yet proposed)    View
12693  CVE-2005-1487  Candidate  ** DISPUTED ** Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable.  Assigned (20050511)  None (candidate not yet proposed)    View

Page 1549 of 20943, showing 5 records out of 104715 total, starting on record 7741, ending on 7745

Actions