NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67036  CVE-2005-1297  Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.    6.8  Medium  2017-01-03  2016-10-17  View
1756  CVE-2008-1816  Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) SDO_UTIL in the Oracle Spatial component, aka DB05; or (2) fine grained auditing in the Audit component, aka DB14. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB05 is SQL injection.    5.5  Medium  2017-01-03  2012-10-22  View
67292  CVE-2005-1565  Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.    Medium  2017-01-03  2016-10-17  View
2012  CVE-2008-2077  Unspecified vulnerability in Plain Black WebGUI 7.4.34 has unknown impact and attack vectors related to "data form list view."    10  High  2017-01-03  2008-09-05  View
67548  CVE-2005-1824  The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.    7.5  High  2017-01-03  2008-09-05  View

Page 15848 of 17672, showing 5 records out of 88360 total, starting on record 79236, ending on 79240

Actions