CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13173  CVE-2005-1967  Candidate  Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.  Assigned (20050614)  None (candidate not yet proposed)    View
13174  CVE-2005-1968  Candidate  Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.  Assigned (20050614)  None (candidate not yet proposed)    View
13175  CVE-2005-1969  Candidate  Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML comment) in a session.  Assigned (20050614)  None (candidate not yet proposed)    View
13176  CVE-2005-1970  Candidate  Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.  Assigned (20050614)  None (candidate not yet proposed)    View
13177  CVE-2005-1971  Candidate  Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.  Assigned (20050614)  None (candidate not yet proposed)    View

Page 19285 of 20943, showing 5 records out of 104715 total, starting on record 96421, ending on 96425

Actions