NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54456 | CVE-2007-2289 | PHP remote file inclusion vulnerability in admin/includes/spaw/dialogs/insert_link.php in download engine (Download-Engine) 1.4.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the spaw_root parameter, a different vector than CVE-2007-2255. NOTE: this may be an issue in SPAW. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
| 55736 | CVE-2007-3586 | Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitrary PHP code into (1) a _score.txt file via the score parameter, or (2) a _setby.txt file via a login cookie, which is then included by games.php. NOTE: programs that use games.php might include (a) snakep.php, (b) tetrisp.php, and possibly other site-specific files. | 2 | 7.5 | High | 2017-01-07 | 2012-11-05 | View | |
| 57272 | CVE-2007-5189 | Multiple SQL injection vulnerabilities in mes_add.php in x-script GuestBook 1.3a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) icq, and (4) website parameters. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
| 58552 | CVE-2007-6557 | Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 58808 | CVE-2006-0068 | SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 14883 of 17672, showing 5 records out of 88360 total, starting on record 74411, ending on 74415