NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53781  CVE-2007-1597  Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.    Medium  2017-01-07  2008-11-13  View
54037  CVE-2007-1866  Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.    10  High  2017-01-07  2012-11-05  View
54293  CVE-2007-2123  Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.    10  High  2017-01-07  2012-10-22  View
54549  CVE-2007-2382  The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."    Medium  2017-01-07  2008-11-13  View
54805  CVE-2007-2641  SQL injection vulnerability in W1L3D4_bolum.asp in W1L3D4 Philboard 0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter, a different vector than CVE-2007-0920.    7.5  High  2017-01-07  2012-11-05  View

Page 1309 of 17672, showing 5 records out of 88360 total, starting on record 6541, ending on 6545

Actions