NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
57015  CVE-2007-4925  The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.    7.5  High  2017-01-07  2013-09-13  View
57271  CVE-2007-5188  Unspecified vulnerability in the XOOPS uploader class in Xoops 2.0.17.1-RC1 and earlier allows remote attackers to upload arbitrary files via unspecified vectors related to improper upload configuration settings in class/uploader.php and class/mimetypes.inc.php, possibly an incomplete blacklist that omits the .php4 extension.    7.5  High  2017-01-07  2011-03-07  View
58551  CVE-2007-6556  Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to default.asp in a news page action or (2) the pageid parameter to default.asp.    7.5  High  2017-01-07  2008-11-15  View
58807  CVE-2006-0067  SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.    7.5  High  2016-12-20  2011-03-07  View
59831  CVE-2006-1109  SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.    7.5  High  2016-12-20  2011-03-07  View

Page 14873 of 17672, showing 5 records out of 88360 total, starting on record 74361, ending on 74365

Actions