NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 70001 | CVE-2005-4403 | SQL injection vulnerability in index.php in Marwel 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the show parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-09-20 | View | |
| 4721 | CVE-2008-4932 | webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root. | 2 | 9 | High | 2017-01-03 | 2009-02-26 | View | |
| 70257 | CVE-2005-4668 | The embedded HSQLDB in ParosProxy before 3.2.7, when running with JDK 1.4.2 before 1.4.2_08, allows local users to execute arbitrary comands via crafted SQL commands that interact with HSQLDB through JDBC, a similar vulnerability to CVE-2003-0845. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 4977 | CVE-2008-5193 | Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-20 | View | |
| 5233 | CVE-2008-5461 | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remote attackers to affect confidentiality, integrity, and availability, related to WLS. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is cross-site scripting. | 2 | 6.8 | Medium | 2017-01-03 | 2012-10-22 | View |
Page 14903 of 17672, showing 5 records out of 88360 total, starting on record 74511, ending on 74515