CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8092  CVE-2003-1268  Candidate  Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.  Assigned (20051116)  None (candidate not yet proposed)    View
14748  CVE-2005-3542  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3508. Reason: This candidate is a reservation duplicate of CVE-2005-3508. Notes: All CVE users should reference CVE-2005-3508 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20051116)  None (candidate not yet proposed)    View
6557  CVE-2002-2175  Candidate  phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username.  Assigned (20051116)  None (candidate not yet proposed)    View
8093  CVE-2003-1269  Candidate  AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.  Assigned (20051116)  None (candidate not yet proposed)    View
14749  CVE-2005-3543  Candidate  SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.  Assigned (20051116)  None (candidate not yet proposed)    View

Page 18737 of 20943, showing 5 records out of 104715 total, starting on record 93681, ending on 93685

Actions