CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13422  CVE-2005-2216  Candidate  PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.  Assigned (20050712)  None (candidate not yet proposed)    View
13423  CVE-2005-2217  Candidate  Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.  Assigned (20050712)  None (candidate not yet proposed)    View
13424  CVE-2005-2218  Candidate  The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed process.  Assigned (20050712)  None (candidate not yet proposed)    View
13425  CVE-2005-2219  Candidate  Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.  Assigned (20050712)  None (candidate not yet proposed)    View
13426  CVE-2005-2220  Candidate  ** DISPUTED ** Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly Commerce does not allow for editing prices nor does it allow for viewing information about clients stored in the database except by the store owner and authorized staff as appointed in the store administration." However, SecurityTracker claims that they have been able to confirm the problem.  Assigned (20050712)  None (candidate not yet proposed)    View

Page 1798 of 20943, showing 5 records out of 104715 total, starting on record 8986, ending on 8990

Actions