CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
15112 | CVE-2005-3908 | Candidate | Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter. | Assigned (20051130) | None (candidate not yet proposed) | View | |
16136 | CVE-2006-0032 | Candidate | Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7. | Assigned (20051130) | None (candidate not yet proposed) | View | |
15113 | CVE-2005-3909 | Candidate | SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter. | Assigned (20051130) | None (candidate not yet proposed) | View | |
16137 | CVE-2006-0033 | Candidate | Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed. | Assigned (20051130) | None (candidate not yet proposed) | View | |
15114 | CVE-2005-3910 | Candidate | merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability. | Assigned (20051130) | None (candidate not yet proposed) | View |
Page 18646 of 20943, showing 5 records out of 104715 total, starting on record 93226, ending on 93230