CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12568  CVE-2005-1362  Candidate  Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6) chkPrice, (7) intPrice, (8) chkCat, or (9) strCat parameters to searchAction.asp.  Assigned (20050428)  None (candidate not yet proposed)    View
12569  CVE-2005-1363  Candidate  Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6) intCatalogID, or (7) page parameter to productsByCategory.asp or (8) intProdID parameter to product.asp.  Assigned (20050428)  None (candidate not yet proposed)    View
12570  CVE-2005-1364  Candidate  Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.  Assigned (20050428)  None (candidate not yet proposed)    View
12544  CVE-2005-1338  Candidate  Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.  Assigned (20050427)  None (candidate not yet proposed)    View
12545  CVE-2005-1339  Candidate  lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.  Assigned (20050427)  None (candidate not yet proposed)    View

Page 19496 of 20943, showing 5 records out of 104715 total, starting on record 97476, ending on 97480

Actions