CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6685  CVE-2002-2303  Candidate  3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.  Assigned (20071017)  None (candidate not yet proposed)    View
6684  CVE-2002-2302  Candidate  3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.  Assigned (20071017)  None (candidate not yet proposed)    View
6683  CVE-2002-2301  Candidate  Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.  Assigned (20071017)  None (candidate not yet proposed)    View
6682  CVE-2002-2300  Candidate  Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command.  Assigned (20071017)  None (candidate not yet proposed)    View
6681  CVE-2002-2299  Candidate  PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter.  Assigned (20071017)  None (candidate not yet proposed)    View

Page 19607 of 20943, showing 5 records out of 104715 total, starting on record 98031, ending on 98035

Actions