Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-16 CVE-2005-4294 Cross-Site Scripting vulnerability in Alkacon OpenCMS Login
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the username in the login page.
network
alkacon
4.3
2005-12-16 CVE-2005-4293 Cross-Site Scripting vulnerability in Kryptronic ClickCartPro CP-APP.CGI
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
network
kryptronic
4.3
2005-12-16 CVE-2005-4292 Cross-Site Scripting vulnerability in CommerceSQL Search Module
Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords parameter in the Quick Find feature.
4.3
2005-12-16 CVE-2005-4291 Cross-Site Scripting vulnerability in ECTOOLS Onlineshop
Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.
network
ectools
4.3
2005-12-16 CVE-2005-4290 Cross-Site Scripting vulnerability in Soft4e ECW-Cart
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.
network
soft4e
4.3
2005-12-16 CVE-2005-4289 Cross-Site Scripting vulnerability in Edatcat Shopping Cart System 0.3
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.
network
edatcat
4.3
2005-12-16 CVE-2005-4288 Cross-Site Scripting vulnerability in MarmaraWeb E-Commerce
Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php.
network
marmaraweb
4.3
2005-12-16 CVE-2005-4287 Remote File Include vulnerability in MarmaraWeb E-Commerce
PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.
network
low complexity
marmaraweb
7.5
2005-12-16 CVE-2005-4286 SQL-Injection vulnerability in PhpLogCon
Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.
network
low complexity
phplogcon
7.5
2005-12-16 CVE-2005-4285 Cross-Site Scripting vulnerability in Dick Copits PDEstore
Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.
network
dick-copits
4.3