NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2072 | CVE-2008-2138 | Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report. | 2 | 5 | Medium | 2017-01-03 | 2009-02-26 | View | |
67608 | CVE-2005-1890 | Unknown vulnerability in Mortiforo before 0.9.1 allows users to access private forums via unknown attack vectors. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
2328 | CVE-2008-2412 | SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
67864 | CVE-2005-2160 | IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
2584 | CVE-2008-2686 | webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename. | 2 | 7.5 | High | 2017-01-03 | 2009-04-08 | View |
Page 1633 of 17672, showing 5 records out of 88360 total, starting on record 8161, ending on 8165