CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13409  CVE-2005-2203  Candidate  login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.  Assigned (20050711)  None (candidate not yet proposed)    View
13410  CVE-2005-2204  Candidate  Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3) the TARGET parameter to login.fcc, and possibly other vectors.  Assigned (20050711)  None (candidate not yet proposed)    View
13411  CVE-2005-2205  Candidate  The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.  Assigned (20050711)  None (candidate not yet proposed)    View
13412  CVE-2005-2206  Candidate  Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.  Assigned (20050711)  None (candidate not yet proposed)    View
13413  CVE-2005-2207  Candidate  Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 1788 of 20943, showing 5 records out of 104715 total, starting on record 8936, ending on 8940

Actions