| 70027 |
CVE-2005-4429 |
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php. |
|
2 |
7.5 |
High |
2017-01-03 |
2008-09-20 |
View
|
| 4747 |
CVE-2008-4958 |
gdrae in gdrae 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gdrae/palabra temporary file. |
|
2 |
6.9 |
Medium |
2017-01-03 |
2009-08-26 |
View
|
| 70283 |
CVE-2005-4694 |
Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute arbitrary code via unknown attack vectors. |
|
2 |
7.5 |
High |
2017-01-03 |
2011-03-07 |
View
|
| 5003 |
CVE-2008-5219 |
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters. |
|
2 |
7.5 |
High |
2017-01-03 |
2009-01-29 |
View
|
| 5259 |
CVE-2008-5510 |
The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the " |