CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12642  CVE-2005-1436  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4) the e parameter to user_login.php, (5) the err parameter to open_submit.php, or (6) the name and subject fields when adding a ticket.  Assigned (20050503)  None (candidate not yet proposed)    View
12643  CVE-2005-1437  Candidate  Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.  Assigned (20050503)  None (candidate not yet proposed)    View
12644  CVE-2005-1438  Candidate  PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.  Assigned (20050503)  None (candidate not yet proposed)    View
12645  CVE-2005-1439  Candidate  Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.  Assigned (20050503)  None (candidate not yet proposed)    View
12646  CVE-2005-1440  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.  Assigned (20050503)  None (candidate not yet proposed)    View

Page 19482 of 20943, showing 5 records out of 104715 total, starting on record 97406, ending on 97410

Actions