NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
54741 | CVE-2007-2577 | Multiple SQL injection vulnerabilities in ACP3 4.0 beta 3 allow remote attackers to execute arbitrary SQL commands via (1) the mode parameter to feeds.php, the (2) form[cat] parameter to (a) news/list/index.php or (b) certain news/details/id_*/action_create/index.php files, or (3) the form[mods][] parameter to search/list/action_search/index.php. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
56789 | CVE-2007-4669 | The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148. | 2 | 4 | Medium | 2017-01-07 | 2008-09-05 | View | |
57045 | CVE-2007-4955 | PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
62421 | CVE-2006-3753 | setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
63189 | CVE-2006-4556 | ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has stated that the product distribution does not include an index.php file. Also, this might be related to CVE-2006-4242. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 1412 of 17672, showing 5 records out of 88360 total, starting on record 7056, ending on 7060