NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
71747 | CVE-2004-1368 | ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. | 2 | 7.8 | High | 2017-07-18 | 2017-07-10 | View | |
72003 | CVE-2004-1624 | Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe). | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
72259 | CVE-2004-1881 | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
72515 | CVE-2004-2138 | Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-10 | View | |
72771 | CVE-2004-2394 | Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks. | 2 | 2.1 | Low | 2017-07-18 | 2017-07-10 | View |
Page 379 of 17672, showing 5 records out of 88360 total, starting on record 1891, ending on 1895