NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53704 | CVE-2007-1520 | The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks. | 2 | 6.8 | Medium | 2017-01-07 | 2008-12-23 | View | |
53960 | CVE-2007-1788 | Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post request. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
55240 | CVE-2007-3086 | Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex. | 2 | 4.9 | Medium | 2017-01-07 | 2008-11-15 | View | |
55496 | CVE-2007-3344 | Multiple cross-site scripting (XSS) vulnerabilities in netjukebox 4.01b allow remote attackers to inject arbitrary web script or HTML via the (1) album_id, (2) order, (3) sort, (4) filter, and (5) genre_id parameters to (a) index.php; and the (6) url parameter to (b) ridirect.php. NOTE: the attack also reveals the installation path. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
55752 | CVE-2007-3602 | The SOAP webservice in vtiger CRM before 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with inactive accounts to access and modify data, as demonstrated by the Thunderbird plugin. | 2 | 5.5 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 15713 of 17672, showing 5 records out of 88360 total, starting on record 78561, ending on 78565