NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54900  CVE-2007-2736  PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.    10  High  2017-01-07  2008-11-15  View
55156  CVE-2007-2997  ** DISPUTED ** Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product."    7.5  High  2017-01-07  2008-11-15  View
56948  CVE-2007-4837  SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2017-01-07  2008-11-15  View
56437  CVE-2007-4312  SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action.    7.5  High  2017-01-07  2008-11-15  View
57717  CVE-2007-5654  LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."    Medium  2017-01-07  2008-11-15  View

Page 15247 of 17672, showing 5 records out of 88360 total, starting on record 76231, ending on 76235

Actions