NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 57789 | CVE-2007-5732 | Directory traversal vulnerability in downloadfile.php in eLouai"s Force Download of media files script, as available on 20071030 and earlier, allows remote attackers to read arbitrary files via the file parameter. NOTE: this issue only occurs in environments where the system administrator has not followed the vendor recommendations that this product should only be used internally. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58301 | CVE-2007-6306 | Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 52414 | CVE-2007-0183 | Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 54718 | CVE-2007-2554 | Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript. | 2 | 7.8 | High | 2017-01-07 | 2008-11-15 | View | |
| 55742 | CVE-2007-3592 | PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields. | 2 | 6.5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 15334 of 17672, showing 5 records out of 88360 total, starting on record 76666, ending on 76670