CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8776 | CVE-2004-0348 | Candidate | SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8778 | CVE-2004-0350 | Candidate | SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8779 | CVE-2004-0351 | Candidate | Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data. | Proposed (20040318) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8671 | CVE-2004-0243 | Candidate | AIX 4.3.3 through AIX 5.1, when direct remote login is disabled, displays a different message if the password is correct, which allows remote attackers to guess the password via brute force methods. | Modified (20050518) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View | |
8673 | CVE-2004-0245 | Candidate | Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero. | Modified (20050710) | ACCEPT(1) Cole | NOOP(3) Armstrong, Cox, Wall | View |
Page 664 of 20943, showing 5 records out of 104715 total, starting on record 3316, ending on 3320