NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
57789  CVE-2007-5732  Directory traversal vulnerability in downloadfile.php in eLouai"s Force Download of media files script, as available on 20071030 and earlier, allows remote attackers to read arbitrary files via the file parameter. NOTE: this issue only occurs in environments where the system administrator has not followed the vendor recommendations that this product should only be used internally.    Medium  2017-01-07  2008-11-15  View
58301  CVE-2007-6306  Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area.    4.3  Medium  2017-01-07  2008-11-15  View
52414  CVE-2007-0183  Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.    6.8  Medium  2017-01-07  2008-11-15  View
54718  CVE-2007-2554  Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript.    7.8  High  2017-01-07  2008-11-15  View
55742  CVE-2007-3592  PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.    6.5  Medium  2017-01-07  2008-11-15  View

Page 15334 of 17672, showing 5 records out of 88360 total, starting on record 76666, ending on 76670

Actions