CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12800  CVE-2005-1594  Candidate  SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
12801  CVE-2005-1595  Candidate  CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.  Assigned (20050516)  None (candidate not yet proposed)    View
12802  CVE-2005-1596  Candidate  index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
12803  CVE-2005-1597  Candidate  Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.  Assigned (20050516)  None (candidate not yet proposed)    View
12804  CVE-2005-1598  Candidate  SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.  Assigned (20050516)  None (candidate not yet proposed)    View

Page 19368 of 20943, showing 5 records out of 104715 total, starting on record 96836, ending on 96840

Actions