NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56564  CVE-2007-4439  PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php.    7.5  High  2017-01-07  2008-11-15  View
58100  CVE-2007-6091  Multiple SQL injection vulnerabilities in files/login.asp in JiRo"s Banner System (JBS) 2.0, and possibly JiRo"s Upload Manager (aka JiRo"s Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field.    7.5  High  2017-01-07  2008-11-15  View
58356  CVE-2007-6361  Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.    Medium  2017-01-07  2008-11-15  View
58612  CVE-2007-6617  Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2008-11-15  View
65524  CVE-2006-6981  3proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blocked account) via unspecified vectors related to NTLM authentication, which causes a password hash to be overwritten.    Medium  2016-12-20  2008-11-15  View

Page 15392 of 17672, showing 5 records out of 88360 total, starting on record 76956, ending on 76960

Actions