CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15206  CVE-2005-4002  Candidate  WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.  Assigned (20051204)  None (candidate not yet proposed)    View
15207  CVE-2005-4003  Candidate  Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. NOTE: the original disclosure was specifically only for an XSS issue, but the CVE description was for SQL injection. Since the original disclosure, SQL injection vectors have been reported. This CVE might be REJECTed or significantly altered pending additional information.  Assigned (20051204)  None (candidate not yet proposed)    View
15208  CVE-2005-4004  Candidate  Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.  Assigned (20051204)  None (candidate not yet proposed)    View
15209  CVE-2005-4005  Candidate  SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Search and Sort option to messages.php.  Assigned (20051204)  None (candidate not yet proposed)    View
15210  CVE-2005-4006  Candidate  SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfile.php, and (5) edit.php.  Assigned (20051204)  None (candidate not yet proposed)    View

Page 18632 of 20943, showing 5 records out of 104715 total, starting on record 93156, ending on 93160

Actions