CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10449  CVE-2004-2023  Candidate  SQL injection vulnerability in login.php in Zen Cart 1.1.2d, 1.1.4 before patch 1, and possibly other versions allows remote attackers to execute arbitrary SQL via the (1) admin_name or (2) admin_pass parameters.  Assigned (20050504)  None (candidate not yet proposed)    View
10450  CVE-2004-2024  Candidate  The distribution of Zen Cart 1.1.4 before patch 2 includes certain debugging code in the Admin password retrieval functionality, which allows attackers to gain administrative privileges via password_forgotten.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10451  CVE-2004-2025  Candidate  SQL injection vulnerability in application_top.php for Zen Cart 1.1.3 before patch 2 may allow remote attackers to execute arbitrary SQL commands via the products_id parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10452  CVE-2004-2026  Candidate  Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.  Assigned (20050504)  None (candidate not yet proposed)    View
10453  CVE-2004-2027  Candidate  Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19459 of 20943, showing 5 records out of 104715 total, starting on record 97291, ending on 97295

Actions