NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55285 | CVE-2007-3131 | Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
58357 | CVE-2007-6362 | SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
59637 | CVE-2006-0910 | Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
60405 | CVE-2006-1700 | Buy.php in Aweb Scripts Seller uses predictable cookies for authentication based on the time and the script number, which allows remote attackers to bypass authentication. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60661 | CVE-2006-1956 | The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 1602 of 17672, showing 5 records out of 88360 total, starting on record 8006, ending on 8010