CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25983 | CVE-2007-2626 | Candidate | ** DISPUTED ** SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE disputes this issue, because "username" does not exist, and the password is not used in any queries. | Assigned (20070511) | None (candidate not yet proposed) | View | |
19898 | CVE-2006-3794 | Candidate | ** DISPUTED ** SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the search field. NOTE: the vendor has disputed this issue, stating "if someone were to type in any sql injection code, that code would never be queried." | Assigned (20060721) | None (candidate not yet proposed) | View | |
63472 | CVE-2013-3525 | Candidate | ** DISPUTED ** SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author"s claims." | Assigned (20130510) | None (candidate not yet proposed) | View | |
24151 | CVE-2007-0794 | Candidate | ** DISPUTED ** SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions. | Assigned (20070206) | None (candidate not yet proposed) | View | |
15699 | CVE-2005-4495 | Candidate | ** DISPUTED ** SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this issue, stating "This information is incorrect, unproven, and potentially slanderous." However, CVE and OSVDB have both performed additional research that suggests that this might be path disclosure from invalid SQL syntax. | Assigned (20051222) | None (candidate not yet proposed) | View |
Page 61 of 20943, showing 5 records out of 104715 total, starting on record 301, ending on 305