NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54900 | CVE-2007-2736 | PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. | 2 | 10 | High | 2017-01-07 | 2008-11-15 | View | |
| 55156 | CVE-2007-2997 | ** DISPUTED ** Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product." | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56948 | CVE-2007-4837 | SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56437 | CVE-2007-4312 | SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 57717 | CVE-2007-5654 | LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection." | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 15247 of 17672, showing 5 records out of 88360 total, starting on record 76231, ending on 76235