CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12794 | CVE-2005-1588 | Candidate | ** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection. | Assigned (20050514) | None (candidate not yet proposed) | View | |
10496 | CVE-2004-2070 | Candidate | The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12800 | CVE-2005-1594 | Candidate | SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12801 | CVE-2005-1595 | Candidate | CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request. | Assigned (20050516) | None (candidate not yet proposed) | View | |
12802 | CVE-2005-1596 | Candidate | index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter. | Assigned (20050516) | None (candidate not yet proposed) | View |
Page 1570 of 20943, showing 5 records out of 104715 total, starting on record 7846, ending on 7850