Show filters
501 Total Results
Displaying 491-500 of 501
Sort by:
Attacker Value
Unknown
CVE-2006-3338
Disclosure Date: July 03, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a direct request to secure/ConfigureReleaseNote.jspa, which are not sanitized before being returned in an error page.
0
Attacker Value
Unknown
CVE-2006-2311
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page.
0
Attacker Value
Unknown
CVE-2006-2310
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.
0
Attacker Value
Unknown
CVE-2005-4298
Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.
0
Attacker Value
Unknown
CVE-2005-4299
Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.
0
Attacker Value
Unknown
CVE-2005-4275
Disclosure Date: December 16, 2005 (last updated February 22, 2025)
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the provenance of this issue is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-3967
Disclosure Date: December 03, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.
0
Attacker Value
Unknown
CVE-2004-0650
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.
0
Attacker Value
Unknown
CVE-2002-0893
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.
0
Attacker Value
Unknown
CVE-2002-0894
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet.
0