NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
57804  CVE-2007-5752  adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.    7.5  High  2017-01-07  2008-09-05  View
58060  CVE-2007-6039  PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.    2.1  Low  2017-01-07  2008-09-05  View
58316  CVE-2007-6321  Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.    4.3  Medium  2017-01-07  2015-01-21  View
58572  CVE-2007-6577  Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.    7.5  High  2017-01-07  2008-11-15  View
58828  CVE-2006-0088  SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.    7.5  High  2016-12-20  2011-03-07  View

Page 14578 of 17672, showing 5 records out of 88360 total, starting on record 72886, ending on 72890

Actions