CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8664  CVE-2004-0236  Candidate  SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field.  Modified (20090127)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8667  CVE-2004-0239  Candidate  SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8668  CVE-2004-0240  Candidate  Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8669  CVE-2004-0241  Candidate  X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8670  CVE-2004-0242  Candidate  X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 22 of 20943, showing 5 records out of 104715 total, starting on record 106, ending on 110

Actions