NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54197  CVE-2007-2027  Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.    4.4  Medium  2017-01-07  2011-03-10  View
54965  CVE-2007-2802  Cross-site scripting (XSS) vulnerability in cp/ps/Main/login/Login in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the d parameter.    4.3  Medium  2017-01-07  2008-11-15  View
55221  CVE-2007-3067  Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the (1) keyshow, (2) sortkey, and (3) show parameters to index.php.    4.3  Medium  2017-01-07  2012-10-30  View
56501  CVE-2007-4376  Unrestricted file upload vulnerability in banner-upload.php in Szymon Kosok Best Top List allows remote attackers to upload and execute arbitrary PHP files in banners/.    6.8  Medium  2017-01-07  2008-11-15  View
56757  CVE-2007-4637  xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.    6.4  Medium  2017-01-07  2008-09-05  View

Page 15049 of 17672, showing 5 records out of 88360 total, starting on record 75241, ending on 75245

Actions