CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12498  CVE-2005-1292  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.  Assigned (20050426)  None (candidate not yet proposed)    View
12499  CVE-2005-1293  Candidate  Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.  Assigned (20050426)  None (candidate not yet proposed)    View
12500  CVE-2005-1294  Candidate  The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.  Assigned (20050426)  None (candidate not yet proposed)    View
12501  CVE-2005-1295  Candidate  include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.  Assigned (20050426)  None (candidate not yet proposed)    View
12502  CVE-2005-1296  Candidate  include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.  Assigned (20050426)  None (candidate not yet proposed)    View

Page 19509 of 20943, showing 5 records out of 104715 total, starting on record 97541, ending on 97545

Actions