Show filters
172 Total Results
Displaying 161-170 of 172
Sort by:
Attacker Value
Unknown

CVE-2007-0514

Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.
0
Attacker Value
Unknown

CVE-2006-6201

Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.
0
Attacker Value
Unknown

CVE-2006-5472

Disclosure Date: October 24, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter in (1) lib/registry.lib.php, (2) lib/sqlcompose.lib.php, and (3) lib/sqlsearch.lib.php.
0
Attacker Value
Unknown

CVE-2006-5471

Disclosure Date: October 24, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) cfg_dir and (2) lib_dir parameters.
0
Attacker Value
Unknown

CVE-2006-5473

Disclosure Date: October 24, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in Description.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the lib_dir parameter. NOTE: this issue is disputed by CVE as of 20061023, since there is no Description.php file included in the product, and the existing "Description" file contains documentation, not functioning code
0
Attacker Value
Unknown

CVE-2006-1884

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
0
Attacker Value
Unknown

CVE-2006-0552

Disclosure Date: February 04, 2006 (last updated February 22, 2025)
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
0
Attacker Value
Unknown

CVE-2005-3204

Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
0
Attacker Value
Unknown

CVE-2005-2291

Disclosure Date: July 18, 2005 (last updated February 22, 2025)
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.
0
Attacker Value
Unknown

CVE-2005-2292

Disclosure Date: July 18, 2005 (last updated February 22, 2025)
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.
0