NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64194 | CVE-2006-5599 | Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE: it is likely that this issue overlaps one of the Oracle VulnIDs covered by CVE-2006-5351. Oracle has not publicly disputed claims by a reliable researcher that this has been fixed by the October 2006 CPU. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
195 | CVE-2008-0210 | Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-05 | View | |
65731 | CVE-2006-7188 | The search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via certain requests, possibly related to the $info{"forum"} variable. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
1987 | CVE-2008-2052 | Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
67523 | CVE-2005-1799 | Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 1298 of 17672, showing 5 records out of 88360 total, starting on record 6486, ending on 6490