NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52381  CVE-2007-0149  EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb.    7.5  High  2017-01-07  2008-11-15  View
53661  CVE-2007-1477  ** DISPUTED ** Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation.    7.5  High  2017-01-07  2008-09-05  View
53917  CVE-2007-1737  Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.    7.5  High  2017-01-07  2012-11-05  View
54429  CVE-2007-2262  Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters. NOTE: this product was originally reported as "File117".    7.5  High  2017-01-07  2011-09-08  View
54685  CVE-2007-2521  PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the locale parameter.    7.5  High  2017-01-07  2011-08-23  View

Page 14592 of 17672, showing 5 records out of 88360 total, starting on record 72956, ending on 72960

Actions