CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8664 | CVE-2004-0236 | Candidate | SQL injection vulnerability in login.asp in thePHOTOtool allows remote attackers to gain unauthorized access via the password field. | Modified (20090127) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8667 | CVE-2004-0239 | Candidate | SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8668 | CVE-2004-0240 | Candidate | Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8669 | CVE-2004-0241 | Candidate | X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
8670 | CVE-2004-0242 | Candidate | X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View |
Page 22 of 20943, showing 5 records out of 104715 total, starting on record 106, ending on 110