CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12103  CVE-2005-0897  Candidate  PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.  Assigned (20050329)  None (candidate not yet proposed)    View
12104  CVE-2005-0898  Candidate  Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter.  Assigned (20050329)  None (candidate not yet proposed)    View
12105  CVE-2005-0899  Candidate  AS/400 running OS400 5.2 installs and enables LDAP by default, which allows remote authenticated users to obtain OS/400 user profiles by performing a search.  Assigned (20050329)  None (candidate not yet proposed)    View
12106  CVE-2005-0900  Candidate  marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.  Assigned (20050329)  None (candidate not yet proposed)    View
12107  CVE-2005-0901  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.  Assigned (20050329)  None (candidate not yet proposed)    View

Page 19594 of 20943, showing 5 records out of 104715 total, starting on record 97966, ending on 97970

Actions