NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 72255 | CVE-2004-1877 | The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
| 72254 | CVE-2004-1876 | The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72253 | CVE-2004-1875 | Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10. | 2 | 9.3 | High | 2017-07-18 | 2017-07-10 | View | |
| 72252 | CVE-2004-1874 | Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72251 | CVE-2004-1873 | SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 15670 of 17672, showing 5 records out of 88360 total, starting on record 78346, ending on 78350