NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52754 | CVE-2007-0530 | ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804. NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
53522 | CVE-2007-1332 | Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme. | 2 | 9.3 | High | 2017-01-07 | 2008-09-05 | View | |
55826 | CVE-2007-3677 | Multiple SQL injection vulnerabilities in Maxsi eVisit Analyst allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) idsp1.pl, (2) ip.pl, and (3) einsite_director.pl. NOTE: this issue can be leveraged for path disclosure from resulting error messages. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
59154 | CVE-2006-0416 | SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
59666 | CVE-2006-0939 | SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 16120 of 17672, showing 5 records out of 88360 total, starting on record 80596, ending on 80600