NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53733 | CVE-2007-1549 | Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via an addImage action, which places scripts into the gallery/shelties/ directory. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
56549 | CVE-2007-4424 | Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribute of an OBJECT element. NOTE: it could be argued that this is not a vulnerability because a dangerous file is not actually launched, but as of 2007, it is generally accepted that web browsers should prompt users before saving dangerous content. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
58341 | CVE-2007-6346 | Cross-site scripting (XSS) vulnerability in Rainboard before 2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
58853 | CVE-2006-0113 | Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
59109 | CVE-2006-0370 | Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 1507 of 17672, showing 5 records out of 88360 total, starting on record 7531, ending on 7535