NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
836 | CVE-2008-0865 | Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
837 | CVE-2008-0866 | Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
838 | CVE-2008-0867 | Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
839 | CVE-2008-0868 | Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
840 | CVE-2008-0869 | Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 168 of 17672, showing 5 records out of 88360 total, starting on record 836, ending on 840