NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65241  CVE-2006-6697  CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.    7.5  High  2016-12-20  2016-10-17  View
218  CVE-2008-0233  Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.    7.5  High  2017-01-03  2008-09-05  View
474  CVE-2008-0499  SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.    7.5  High  2017-01-03  2011-03-07  View
66778  CVE-2005-1029  Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.    7.5  High  2017-07-18  2017-07-10  View
67034  CVE-2005-1295  include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.    7.5  High  2017-01-03  2016-10-17  View

Page 16283 of 17672, showing 5 records out of 88360 total, starting on record 81411, ending on 81415

Actions