NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65408 | CVE-2006-6865 | Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitrary files via a %c0%ae. (Unicode dot dot) in the path parameter, which bypasses the checks for ".." sequences. | 2 | 7.8 | High | 2016-12-20 | 2011-03-07 | View | |
65665 | CVE-2006-7122 | Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
70529 | CVE-2004-0061 | WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
73089 | CVE-2004-2712 | Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data." | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
59009 | CVE-2006-0269 | Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package. | 2 | 5.5 | Medium | 2016-12-20 | 2012-10-22 | View |
Page 16918 of 17672, showing 5 records out of 88360 total, starting on record 84586, ending on 84590