CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13341  CVE-2005-2135  Candidate  SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.  Assigned (20050705)  None (candidate not yet proposed)    View
13342  CVE-2005-2136  Candidate  Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.  Assigned (20050705)  None (candidate not yet proposed)    View
13343  CVE-2005-2137  Candidate  Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.  Assigned (20050705)  None (candidate not yet proposed)    View
13344  CVE-2005-2138  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.  Assigned (20050705)  None (candidate not yet proposed)    View
13345  CVE-2005-2139  Candidate  PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.  Assigned (20050705)  None (candidate not yet proposed)    View

Page 19173 of 20943, showing 5 records out of 104715 total, starting on record 95861, ending on 95865

Actions