NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58135  CVE-2007-6128  SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL commands via the idevent parameter.    7.5  High  2017-01-07  2011-03-07  View
58391  CVE-2007-6396  Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user"s php file for this account. NOTE: similar code injection might be possible in a user profile.    7.5  High  2017-01-07  2013-07-27  View
58647  CVE-2007-6652  cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer).    7.5  High  2017-01-07  2008-11-15  View
58903  CVE-2006-0163  SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field. NOTE: This is a different vulnerability than CVE-2005-3792.    7.5  High  2016-12-20  2011-03-07  View
59159  CVE-2006-0421  By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.    4.6  Medium  2016-12-20  2011-03-07  View

Page 1433 of 17672, showing 5 records out of 88360 total, starting on record 7161, ending on 7165

Actions