NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56498  CVE-2007-4373  The server in Babo Violent 2 2.08.00 and earlier does not properly implement password protection, which might allow remote attackers to bypass authentication by reconnecting after a connection closes.    6.8  Medium  2017-01-07  2008-09-05  View
57522  CVE-2007-5457  Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) install.joomla_flash_uploader.php and (2) uninstall.joomla_flash_uploader.php.    6.8  Medium  2017-01-07  2008-09-05  View
59570  CVE-2006-0840  manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a " (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519.    Medium  2016-12-20  2008-09-05  View
60850  CVE-2006-2145  Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.    6.4  Medium  2016-12-20  2008-09-05  View
61362  CVE-2006-2677  SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path information.    Medium  2016-12-20  2008-09-05  View

Page 1191 of 17672, showing 5 records out of 88360 total, starting on record 5951, ending on 5955

Actions