CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13412  CVE-2005-2206  Candidate  Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.  Assigned (20050711)  None (candidate not yet proposed)    View
13413  CVE-2005-2207  Candidate  Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.  Assigned (20050711)  None (candidate not yet proposed)    View
13414  CVE-2005-2208  Candidate  PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.  Assigned (20050711)  None (candidate not yet proposed)    View
13415  CVE-2005-2209  Candidate  Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.  Assigned (20050711)  None (candidate not yet proposed)    View
13416  CVE-2005-2210  Candidate  Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.  Assigned (20050711)  None (candidate not yet proposed)    View

Page 19150 of 20943, showing 5 records out of 104715 total, starting on record 95746, ending on 95750

Actions