NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53451 | CVE-2007-1248 | Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
54219 | CVE-2007-2049 | Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-13 | View | |
54475 | CVE-2007-2308 | Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
55243 | CVE-2007-3089 | Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568. | 2 | 4.3 | Medium | 2017-01-07 | 2013-07-06 | View | |
56267 | CVE-2007-4136 | The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections. | 2 | 5 | Medium | 2017-01-07 | 2010-11-12 | View |
Page 15817 of 17672, showing 5 records out of 88360 total, starting on record 79081, ending on 79085