CSV
184,096 results for "vulnerability" Page 163
CVE-2005-3437

Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# DB01.

Nov 2, 2005 2 affected product(s) NVD
10.0
CVSS
5.1%
EPSS
⚡ 41.5
CVE-2005-3440

Unspecified vulnerability in Database Scheduler in Oracle Database Server 10g up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB08.

Nov 2, 2005 1 affected product(s) NVD
10.0
CVSS
5.1%
EPSS
⚡ 41.5
CVE-2005-3446

Unspecified vulnerability in Internet Directory in Oracle Database Server 9i up to 9.2.0.6 and Application Server 9.0.2.3 up to 10.1.2.0 has unknown impact and attack vectors, aka Oracle Vuln# DB32 and AS06.

Nov 2, 2005 7 affected product(s) NVD
10.0
CVSS
5.1%
EPSS
⚡ 41.5
CVE-2005-3443

Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB17.

Nov 2, 2005 4 affected product(s) NVD
10.0
CVSS
3.8%
EPSS
⚡ 41.1
CVE-2005-3447

Unspecified vulnerability in Single Sign-On in Oracle Database Server 10g up to 10.1.0.4.2 and Application Server 9.0.2.3 up to 9.0.4.2 has unknown impact and attack vectors, aka Oracle Vuln# DB33 and AS08.

Nov 2, 2005 NVD
10.0
CVSS
2.9%
EPSS
⚡ 40.9
CVE-2005-3441

Unspecified vulnerability in Intelligent Agent in Oracle Database Server 9i up to 9.0.1.5 has unknown impact and attack vectors, aka Oracle Vuln# DB14.

Nov 2, 2005 NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2005-3435 CRITICAL

admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.

Nov 2, 2005 1 affected product(s) NVD
9.8
CVSS
2.3%
EPSS
⚡ 39.9
CVE-2005-3405

ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.

Nov 1, 2005 NVD
7.5
CVSS
8.1%
EPSS
⚡ 32.4
CVE-2005-3392

Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.

Nov 1, 2005 54 affected product(s) NVD
7.5
CVSS
6.9%
EPSS
⚡ 32.1
CVE-2005-3388

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

Nov 1, 2005 48 affected product(s) NVD
4.3
CVSS
48.9%
EPSS
⚡ 31.9
CVE-2005-3363

SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

Oct 30, 2005 2 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31
CVE-2005-3393

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

Nov 1, 2005 4 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31
CVE-2005-3395

SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.

Nov 1, 2005 1 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.8
CVE-2005-3419

SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.

Nov 1, 2005 27 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2005-3383

SQL injection vulnerability in Techno Dreams Announcement script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3384

SQL injection vulnerability in Techno Dreams Guest Book script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3385

SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3386

SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.

Oct 30, 2005 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2005-3430

Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.

Nov 2, 2005 2 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2005-3407

SQL injection vulnerability in phpESP 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Nov 1, 2005 23 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
← Previous Page 163 of 9205 Next →