Page 84 of 571 results (0.011 seconds)

CVSS: 10.0EPSS: 0%CPEs: 2EXPL: 0

Unspecified vulnerability in the Database Control component in Oracle Database 10.1.0.5 and 10.2.0.3, and Enterprise Manager, has unknown impact and remote attack vectors, aka EM01. Vulnerabilidad no especificada en el componente Database Control para Oracle Database 10.1.0.5 y 10.2.0.3, y Enterprise Manager, tiene impacto y vectores de ataque remotos desconocidos, también conocido como EM01. • http://marc.info/?l=bugtraq&m=119332677525918&w=2 http://secunia.com/advisories/27251 http://secunia.com/advisories/27409 http://www.oracle.com/technetwork/topics/security/cpuoct2007-092913.html http://www.securitytracker.com/id?1018823 http://www.us-cert.gov/cas/techalerts/TA07-290A.html http://www.vupen.com/english/advisories/2007/3524 http://www.vupen.com/english/advisories/2007/3626 •

CVSS: 6.5EPSS: 97%CPEs: 1EXPL: 3

SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain. Vulnerabilidad de inyección SQL en el Workspace Manager para las Bases de Datos Oracle anteriores a la OWM 10.2.0.4.1, OWM 10.1.0.8.0 y OWM 9.2.0.8.0 permite a atacantes remotos ejecutar comandos SQL de su elección a través del procedimiento FINDRICSET en el paquete LT. NOTA: esta vulnerabilidad esté, probablemente, cubierta por la CVE-2007-5510, pero no hay suficientes detalles para tener certeza. • https://www.exploit-db.com/exploits/4572 https://www.exploit-db.com/exploits/4570 https://www.exploit-db.com/exploits/4571 http://marc.info/?l=bugtraq&m=119332677525918&w=2 http://osvdb.org/40079 http://secunia.com/advisories/27251 http://secunia.com/advisories/27409 http://securityreason.com/securityalert/3245 http://www.securityfocus.com/archive/1/482429/100/0/threaded http://www.securityfocus.com/bid/26098 http://www.securitytracker.com/id?1018823 http://www • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.2, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB27. Vulnerabilidad no especificada en el componente Spatial de Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.2, y 10.2.0.3 tiene impacto y vectores de ataque remotos desconocidos, también conocida como DB27. • http://marc.info/?l=bugtraq&m=119332677525918&w=2 http://secunia.com/advisories/27251 http://secunia.com/advisories/27409 http://www.oracle.com/technetwork/topics/security/cpuoct2007-092913.html http://www.securitytracker.com/id?1018823 http://www.us-cert.gov/cas/techalerts/TA07-290A.html http://www.vupen.com/english/advisories/2007/3524 http://www.vupen.com/english/advisories/2007/3626 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV and 10.2.0.3 has unknown impact and remote attack vectors, aka DB21. Vulnerabilidad no especificada en en el componente Oracle Database Vault de Oracle Database 9.2.0.8DV y 10.2.0.3 tiene impacto y vectores de ataque remotos desconocidos, también conocida como DB21. • http://marc.info/?l=bugtraq&m=119332677525918&w=2 http://secunia.com/advisories/27251 http://secunia.com/advisories/27409 http://www.oracle.com/technetwork/topics/security/cpuoct2007-092913.html http://www.securitytracker.com/id?1018823 http://www.us-cert.gov/cas/techalerts/TA07-290A.html http://www.vupen.com/english/advisories/2007/3524 http://www.vupen.com/english/advisories/2007/3626 •

CVSS: 4.3EPSS: 1%CPEs: 3EXPL: 2

Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by accessing (1) ap.html and (2) filter_ip.html. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el interfaz de administración de Buffalo AirStation WHR-G54S 1.20 permite a atacantes remotos realizar cambios de configuración como administradores mediante peticiones HTTP a determinadas páginas HTML en el parámetro res con un parámetro inp en la petición a cgi-bin/cgi, como se ha demostrado accediendo a (1)ap.html y (2) filter_ip.html. • http://osvdb.org/37665 http://secunia.com/advisories/26712 http://securityreason.com/securityalert/3117 http://www.louhi.fi/advisory/buffalo_070907.txt http://www.securityfocus.com/archive/1/478795/100/0/threaded http://www.securityfocus.com/archive/1/478801/100/0/threaded http://www.securityfocus.com/bid/25588 https://exchange.xforce.ibmcloud.com/vulnerabilities/36492 • CWE-352: Cross-Site Request Forgery (CSRF) •