NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 55441 | CVE-2007-3289 | PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 55953 | CVE-2007-3809 | Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory.php, and other unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56209 | CVE-2007-4078 | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Text Ads Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) r parameter to (a) forgot_uid.php, the (2) query or (3) sk parameter to (b) search_results.php, or (4) the pageId parameter to (c) website_page.php. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 56721 | CVE-2007-4601 | A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58257 | CVE-2007-6260 | The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation, if performed using the Database Configuration Assistant (DBCA), most accounts are disabled or their passwords are changed. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 15277 of 17672, showing 5 records out of 88360 total, starting on record 76381, ending on 76385