NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 55635 | CVE-2007-3484 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this issue is disputed by the Google Security Team, who states that "Google does not provide the "search.php" script referenced. When a user creates a custom search engine, we provide them with a block of javascript to include on their site. Some users write additional code around this block of javascript to further customize their website." | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 56915 | CVE-2007-4804 | Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171. NOTE: the scripts may be accessed through requests to the product"s top-level default URI, using the pilih parameter, in some circumstances. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 57171 | CVE-2007-5088 | Cross-site scripting (XSS) vulnerability in search/cust_bill_event.cgi in Freeside 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the failed parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57939 | CVE-2007-5914 | Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated administrators to inject arbitrary PHP code via the DEBUG parameter, which can be executed by accessing config.inc.php. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2007-5913. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 59987 | CVE-2006-1273 | ** DISPUTED ** Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source. NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extension," and Mozilla also confirmed that this is not an issue in Firefox itself. | 2 | 7.8 | High | 2016-12-20 | 2008-11-15 | View |
Page 15215 of 17672, showing 5 records out of 88360 total, starting on record 76071, ending on 76075