CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13394  CVE-2005-2188  Candidate  McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.  Assigned (20050710)  None (candidate not yet proposed)    View
13395  CVE-2005-2189  Candidate  Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.  Assigned (20050710)  None (candidate not yet proposed)    View
13396  CVE-2005-2190  Candidate  Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp.  Assigned (20050710)  None (candidate not yet proposed)    View
10581  CVE-2004-2155  Candidate  Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.  Assigned (20050710)  None (candidate not yet proposed)    View
13397  CVE-2005-2191  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.  Assigned (20050710)  None (candidate not yet proposed)    View

Page 19161 of 20943, showing 5 records out of 104715 total, starting on record 95801, ending on 95805

Actions