CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10036  CVE-2004-1608  Candidate  SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.  Assigned (20050220)  None (candidate not yet proposed)    View
10037  CVE-2004-1609  Candidate  SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.  Assigned (20050220)  None (candidate not yet proposed)    View
10038  CVE-2004-1610  Candidate  SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.  Assigned (20050220)  None (candidate not yet proposed)    View
10039  CVE-2004-1611  Candidate  SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.  Assigned (20050220)  None (candidate not yet proposed)    View
10040  CVE-2004-1612  Candidate  Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.  Assigned (20050220)  None (candidate not yet proposed)    View

Page 19745 of 20943, showing 5 records out of 104715 total, starting on record 98721, ending on 98725

Actions