CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14410  CVE-2005-3204  Candidate  Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.  Assigned (20051014)  None (candidate not yet proposed)    View
14411  CVE-2005-3205  Candidate  Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.  Assigned (20051014)  None (candidate not yet proposed)    View
14412  CVE-2005-3206  Candidate  iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command.  Assigned (20051014)  None (candidate not yet proposed)    View
14413  CVE-2005-3207  Candidate  The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command.  Assigned (20051014)  None (candidate not yet proposed)    View
14414  CVE-2005-3208  Candidate  Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.  Assigned (20051014)  None (candidate not yet proposed)    View

Page 18843 of 20943, showing 5 records out of 104715 total, starting on record 94211, ending on 94215

Actions