CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13268  CVE-2005-2062  Candidate  Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.  Assigned (20050629)  None (candidate not yet proposed)    View
6357  CVE-2002-1975  Candidate  Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.  Assigned (20050629)  None (candidate not yet proposed)    View
13269  CVE-2005-2063  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.  Assigned (20050629)  None (candidate not yet proposed)    View
6358  CVE-2002-1976  Candidate  ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.  Assigned (20050629)  None (candidate not yet proposed)    View
13270  CVE-2005-2064  Candidate  Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.  Assigned (20050629)  None (candidate not yet proposed)    View

Page 19229 of 20943, showing 5 records out of 104715 total, starting on record 96141, ending on 96145

Actions