NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55061 | CVE-2007-2901 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
55317 | CVE-2007-3163 | Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658. | 2 | 5 | Medium | 2017-01-07 | 2012-10-30 | View | |
55573 | CVE-2007-3421 | The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP before 0.9.9.7 do not verify presence of users in memberlist.dat, which has unknown impact and remote attack vectors. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
55829 | CVE-2007-3680 | Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable. | 2 | 7.2 | High | 2017-01-07 | 2012-10-30 | View | |
56085 | CVE-2007-3949 | mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings. | 2 | 8.3 | High | 2017-01-07 | 2012-10-30 | View |
Page 1310 of 17672, showing 5 records out of 88360 total, starting on record 6546, ending on 6550