CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
17202 | CVE-2006-1098 | Candidate | ** DISPUTED ** Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher"s blog, but research by CVE suggests that this might be a legitimate problem. | Assigned (20060309) | None (candidate not yet proposed) | View | |
15122 | CVE-2005-3918 | Candidate | ** DISPUTED ** Multiple SQL injection vulnerabilities in OvBB 0.08a allow remote attackers to execute arbitrary SQL commands via the (1) threadid parameter to thread.php and (2) userid parameter to profile.php. NOTE: the vendor disputes these issues, saying "these reports are completely unsubstantial." | Assigned (20051130) | None (candidate not yet proposed) | View | |
18034 | CVE-2006-1930 | Candidate | ** DISPUTED ** Multiple SQL injection vulnerabilities in userscript.php in Green Minute 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) huserid, (2) pituus, or (3) date parameters. NOTE: this issue has been disputed by the vendor, saying "those parameters mentioned ARE checked (preg_match) before they are used in SQL-query... If someone decided to add SQL-injection stuff to certain parameter, they would see an error text, but only because _nothing_ was passed inside that parameter (to MySQL-database)." As allowed by the vendor, CVE investigated this report on 20060525 and found that the demo site demonstrated a non-sensitive SQL error when given standard SQL injection manipulations. | Assigned (20060420) | None (candidate not yet proposed) | View | |
21264 | CVE-2006-5160 | Candidate | ** DISPUTED ** Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not." | Assigned (20061003) | None (candidate not yet proposed) | View | |
21140 | CVE-2006-5036 | Candidate | ** DISPUTED ** MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server"s IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability." | Assigned (20060927) | None (candidate not yet proposed) | View |
Page 35 of 20943, showing 5 records out of 104715 total, starting on record 171, ending on 175