CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2805 | CVE-2000-1238 | Candidate | BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages. | Assigned (20051116) | None (candidate not yet proposed) | View | |
2804 | CVE-2000-1237 | Candidate | The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing. | Assigned (20050714) | None (candidate not yet proposed) | View | |
2803 | CVE-2000-1236 | Candidate | SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL. | Assigned (20050714) | None (candidate not yet proposed) | View | |
2802 | CVE-2000-1235 | Candidate | The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files. | Assigned (20050714) | None (candidate not yet proposed) | View | |
2801 | CVE-2000-1234 | Candidate | violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters. | Assigned (20050714) | None (candidate not yet proposed) | View |
Page 20383 of 20943, showing 5 records out of 104715 total, starting on record 101911, ending on 101915