NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53961 | CVE-2007-1789 | Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
54473 | CVE-2007-2306 | Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
55753 | CVE-2007-3603 | SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute arbitrary SQL commands via the assigned_user_id parameter in a Potentials ListView action to index.php. | 2 | 6.5 | Medium | 2017-01-07 | 2008-11-13 | View | |
56265 | CVE-2007-4134 | Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive. | 2 | 6.8 | Medium | 2017-01-07 | 2010-08-21 | View | |
57545 | CVE-2007-5480 | Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 15748 of 17672, showing 5 records out of 88360 total, starting on record 78736, ending on 78740