NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58400 | CVE-2007-6405 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) "+" character, (2) "." character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already covered by CVE-2007-3407. | 2 | 6.4 | Medium | 2017-01-07 | 2008-11-15 | View | |
58656 | CVE-2007-6661 | 2z project 0.9.6.1 allows attackers to change the password without supplying the old password. | 2 | 6.4 | Medium | 2017-01-07 | 2008-09-05 | View | |
59168 | CVE-2006-0430 | Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown). | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
59936 | CVE-2006-1222 | Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60192 | CVE-2006-1483 | Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1188 of 17672, showing 5 records out of 88360 total, starting on record 5936, ending on 5940