NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65241 | CVE-2006-6697 | CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
218 | CVE-2008-0233 | Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
474 | CVE-2008-0499 | SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
66778 | CVE-2005-1029 | Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67034 | CVE-2005-1295 | include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View |
Page 16283 of 17672, showing 5 records out of 88360 total, starting on record 81411, ending on 81415