CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6685 | CVE-2002-2303 | Candidate | 3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data. | Assigned (20071017) | None (candidate not yet proposed) | View | |
6684 | CVE-2002-2302 | Candidate | 3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field. | Assigned (20071017) | None (candidate not yet proposed) | View | |
6683 | CVE-2002-2301 | Candidate | Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database. | Assigned (20071017) | None (candidate not yet proposed) | View | |
6682 | CVE-2002-2300 | Candidate | Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command. | Assigned (20071017) | None (candidate not yet proposed) | View | |
6681 | CVE-2002-2299 | Candidate | PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | Assigned (20071017) | None (candidate not yet proposed) | View |
Page 19607 of 20943, showing 5 records out of 104715 total, starting on record 98031, ending on 98035