NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52768 | CVE-2007-0544 | Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web script or HTML via the Subject field, a different vector than CVE-2006-2949. | 2 | 6 | Medium | 2017-01-07 | 2011-02-02 | View | |
53024 | CVE-2007-0807 | Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the "who"s online" feature. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
54048 | CVE-2007-1878 | Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
55072 | CVE-2007-2912 | Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to see the infraction "red flag" for a deleted user. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
55328 | CVE-2007-3174 | Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the adtype parameter, a different vector than CVE-2006-1980. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 1186 of 17672, showing 5 records out of 88360 total, starting on record 5926, ending on 5930