NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55566 | CVE-2007-3414 | Multiple cross-site scripting (XSS) vulnerabilities in access2asp 4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) od and (2) search parameters to (a) suppliersList.asp and (b) contactsList.asp. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
55822 | CVE-2007-3672 | Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
56078 | CVE-2007-3942 | ** DISPUTED ** Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray are defined before use. | 2 | 5.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
56334 | CVE-2007-4203 | Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter. | 2 | 9.3 | High | 2017-01-07 | 2008-11-15 | View | |
56590 | CVE-2007-4465 | Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View |
Page 1012 of 17672, showing 5 records out of 88360 total, starting on record 5056, ending on 5060