CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13394 | CVE-2005-2188 | Candidate | McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack. | Assigned (20050710) | None (candidate not yet proposed) | View | |
13395 | CVE-2005-2189 | Candidate | Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys. | Assigned (20050710) | None (candidate not yet proposed) | View | |
13396 | CVE-2005-2190 | Candidate | Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp. | Assigned (20050710) | None (candidate not yet proposed) | View | |
10581 | CVE-2004-2155 | Candidate | Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php. | Assigned (20050710) | None (candidate not yet proposed) | View | |
13397 | CVE-2005-2191 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp. | Assigned (20050710) | None (candidate not yet proposed) | View |
Page 19161 of 20943, showing 5 records out of 104715 total, starting on record 95801, ending on 95805