CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10836  CVE-2004-2410  Candidate  Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of service (null pointer dereference).  Assigned (20050818)  None (candidate not yet proposed)    View
10837  CVE-2004-2411  Candidate  The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use <script> tags, as demonstrated via javascript in IMG tags to (1) the cat parameter in shopdisplayproducts.asp or (2) the msg parameter in shoperror.asp, and possibly other vectors.  Assigned (20050818)  None (candidate not yet proposed)    View
10838  CVE-2004-2412  Candidate  Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via the catalogid parameter in (1) shopreviewlist.asp and (2) shopreviewadd.asp.  Assigned (20050818)  None (candidate not yet proposed)    View
10839  CVE-2004-2413  Candidate  SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp.  Assigned (20050818)  None (candidate not yet proposed)    View
10840  CVE-2004-2414  Candidate  Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.  Assigned (20050818)  None (candidate not yet proposed)    View

Page 18976 of 20943, showing 5 records out of 104715 total, starting on record 94876, ending on 94880

Actions