NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 56217 | CVE-2007-4086 | Multiple SQL injection vulnerabilities in AlstraSoft Video Share Enterprise allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter to gmembers.php, or (2) the UID parameter to (a) uvideos.php, (b) ugroups.php, (c) uprofile.php, (d) ufavour.php, (e) ufriends.php, or (f) uplaylist.php. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 56729 | CVE-2007-4609 | eyeOS uses predictable checksum values in the checknum parameter for access control, which allows remote attackers to register many accounts via doCreateUser actions, add many eyeBoard messages via addMsg actions, and cause a denial of service or conduct certain unauthorized activities, by guessing valid parameter values. | 2 | 6.4 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57241 | CVE-2007-5158 | The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57497 | CVE-2007-5432 | Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 58009 | CVE-2007-5985 | Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 15289 of 17672, showing 5 records out of 88360 total, starting on record 76441, ending on 76445