NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 57823 | CVE-2007-5772 | Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue. | 2 | 6 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58079 | CVE-2007-6058 | Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
| 58335 | CVE-2007-6340 | Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords. | 2 | 2.1 | Low | 2017-01-07 | 2008-09-05 | View | |
| 58591 | CVE-2007-6596 | ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
| 58847 | CVE-2006-0107 | SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 15140 of 17672, showing 5 records out of 88360 total, starting on record 75696, ending on 75700