CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7349  CVE-2003-0522  Candidate  Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.  Assigned (20030708)  None (candidate not yet proposed)    View
7350  CVE-2003-0523  Candidate  Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.  Assigned (20030708)  None (candidate not yet proposed)    View
7351  CVE-2003-0524  Candidate  Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.  Assigned (20030708)  None (candidate not yet proposed)    View
7352  CVE-2003-0525  Candidate  The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.  Assigned (20030708)  None (candidate not yet proposed)    View
7353  CVE-2003-0526  Candidate  Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."  Assigned (20030708)  None (candidate not yet proposed)    View

Page 719 of 20943, showing 5 records out of 104715 total, starting on record 3591, ending on 3595

Actions