CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15112  CVE-2005-3908  Candidate  Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.  Assigned (20051130)  None (candidate not yet proposed)    View
16136  CVE-2006-0032  Candidate  Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.  Assigned (20051130)  None (candidate not yet proposed)    View
15113  CVE-2005-3909  Candidate  SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.  Assigned (20051130)  None (candidate not yet proposed)    View
16137  CVE-2006-0033  Candidate  Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.  Assigned (20051130)  None (candidate not yet proposed)    View
15114  CVE-2005-3910  Candidate  merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.  Assigned (20051130)  None (candidate not yet proposed)    View

Page 18646 of 20943, showing 5 records out of 104715 total, starting on record 93226, ending on 93230

Actions