NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80140 | CVE-2002-1148 | The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet. | 2 | 5 | Medium | 2017-01-05 | 2016-10-17 | View | |
14860 | CVE-2010-3481 | Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable. | 2 | 6.8 | Medium | 2017-01-18 | 2010-09-23 | View | |
80396 | CVE-2002-1443 | The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user"s input into the toolbar via an "onkeydown" event handler. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
15116 | CVE-2010-3771 | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI. | 2 | 6.8 | Medium | 2017-01-18 | 2011-07-18 | View | |
80652 | CVE-2002-1700 | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 839 of 17672, showing 5 records out of 88360 total, starting on record 4191, ending on 4195