CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8670  CVE-2004-0242  Candidate  X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8669  CVE-2004-0241  Candidate  X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8668  CVE-2004-0240  Candidate  Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8667  CVE-2004-0239  Candidate  SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8666  CVE-2004-0238  Candidate  Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.  Proposed (20040318)  ACCEPT(1) Armstrong | NOOP(3) Cole, Cox, Wall    View

Page 19210 of 20943, showing 5 records out of 104715 total, starting on record 96046, ending on 96050

Actions