CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13341 | CVE-2005-2135 | Candidate | SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters. | Assigned (20050705) | None (candidate not yet proposed) | View | |
13342 | CVE-2005-2136 | Candidate | Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users. | Assigned (20050705) | None (candidate not yet proposed) | View | |
13343 | CVE-2005-2137 | Candidate | Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors. | Assigned (20050705) | None (candidate not yet proposed) | View | |
13344 | CVE-2005-2138 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message. | Assigned (20050705) | None (candidate not yet proposed) | View | |
13345 | CVE-2005-2139 | Candidate | PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter. | Assigned (20050705) | None (candidate not yet proposed) | View |
Page 19173 of 20943, showing 5 records out of 104715 total, starting on record 95861, ending on 95865