NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
1245  CVE-2008-1286  Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.    7.8  High  2017-01-03  2011-03-07  View
66781  CVE-2005-1032  ** REJECT ** cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters. NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type and severity. The vendor has disputed this issue, saying "These reports are credited to malicious person we refused to hire. We have not taken legal action against him only because he is located in India. The vulnerabilites reported can not be reproduced, hence information you provide is contrary to fact." Further investigation by CVE personnel shows that an invalid SQL syntax error could be generated, but it only reveals portions of underlying database structure, which is already available in documentation from the vendor, and it does not appear to lead to path disclosure. Therefore, this issue is not a vulnerability or an exposure, and it probably should be REJECTED.        2017-01-03  2008-09-10  View
1501  CVE-2008-1557  BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which calls the phpinfo function.    Medium  2017-01-03  2008-09-05  View
67037  CVE-2005-1298  The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.    7.5  High  2017-01-03  2016-10-17  View
1757  CVE-2008-1817  Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 have unknown impact and remote attack vectors related to (1) SDO_IDX in the Spatial component, aka DB07; and (2) Core RDBMS, aka DB10. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB07 is SQL injection.    High  2017-01-03  2012-10-22  View

Page 15857 of 17672, showing 5 records out of 88360 total, starting on record 79281, ending on 79285

Actions