NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67801  CVE-2005-2092  BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."    4.3  Medium  2017-07-18  2017-07-10  View
68569  CVE-2005-2894  Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.    4.3  Medium  2017-07-18  2017-07-10  View
70873  CVE-2004-0426  rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.    Medium  2017-07-18  2017-07-10  View
71129  CVE-2004-0702  DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.    Medium  2017-07-18  2017-07-10  View
71385  CVE-2004-0983  The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.    Medium  2017-07-18  2017-07-10  View

Page 17286 of 17672, showing 5 records out of 88360 total, starting on record 86426, ending on 86430

Actions