NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 56510 | CVE-2007-4385 | OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the validation routines. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57022 | CVE-2007-4932 | admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 57278 | CVE-2007-5196 | Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 57790 | CVE-2007-5733 | Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attackers to upload and execute arbitrary PHP code via a ServerPath parameter specifying a filename with a double extension. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 53439 | CVE-2007-1236 | sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[] or (2) sxYear[] parameter to calendar.php, or the (3) page[] parameter to calendar_events.php, which reveals the path in various error messages. | 2 | 6.4 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 15335 of 17672, showing 5 records out of 88360 total, starting on record 76671, ending on 76675