NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67801 | CVE-2005-2092 | BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling." | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
68569 | CVE-2005-2894 | Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
70873 | CVE-2004-0426 | rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71129 | CVE-2004-0702 | DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
71385 | CVE-2004-0983 | The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17286 of 17672, showing 5 records out of 88360 total, starting on record 86426, ending on 86430