CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13173 | CVE-2005-1967 | Candidate | Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13174 | CVE-2005-1968 | Candidate | Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13175 | CVE-2005-1969 | Candidate | Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML comment) in a session. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13176 | CVE-2005-1970 | Candidate | Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature. | Assigned (20050614) | None (candidate not yet proposed) | View | |
13177 | CVE-2005-1971 | Candidate | Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter. | Assigned (20050614) | None (candidate not yet proposed) | View |
Page 19285 of 20943, showing 5 records out of 104715 total, starting on record 96421, ending on 96425