NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55726  CVE-2007-3576  ** DISPUTED ** Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names with 10 or more characters, which might allow remote attackers to bypass certain XSS protection schemes. NOTE: other researchers dispute the significance of this issue, stating "this only works when typed in the address bar."    4.3  Medium  2017-01-07  2008-11-15  View
57518  CVE-2007-5453  Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by (1) admin.php, (2) click.php, (3) download.php, and unspecified other files, as demonstrated by modifying _options through a backup restore action in admin.php.    8.5  High  2017-01-07  2008-11-15  View
58030  CVE-2007-6006  TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.    10  High  2017-01-07  2008-11-15  View
58542  CVE-2007-6547  RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.    6.8  Medium  2017-01-07  2008-11-15  View
52911  CVE-2007-0689  MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.    Medium  2017-01-07  2008-11-15  View

Page 15317 of 17672, showing 5 records out of 88360 total, starting on record 76581, ending on 76585

Actions