CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12794  CVE-2005-1588  Candidate  ** DISPUTED ** SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection.  Assigned (20050514)  None (candidate not yet proposed)    View
10496  CVE-2004-2070  Candidate  The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.  Assigned (20050516)  None (candidate not yet proposed)    View
12800  CVE-2005-1594  Candidate  SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
12801  CVE-2005-1595  Candidate  CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.  Assigned (20050516)  None (candidate not yet proposed)    View
12802  CVE-2005-1596  Candidate  index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 1570 of 20943, showing 5 records out of 104715 total, starting on record 7846, ending on 7850

Actions