NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56090 | CVE-2007-3954 | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking SeaMonkey.exe, a related issue to CVE-2007-3670. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
56346 | CVE-2007-4217 | Stack-based buffer overflow in the domacro function in ftp in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long parameter to a macro, as demonstrated by executing a macro via the "$" command. | 2 | 7.2 | High | 2017-01-07 | 2011-03-07 | View | |
56602 | CVE-2007-4479 | Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
56858 | CVE-2007-4741 | Cross-site scripting (XSS) vulnerability in admin/adminusers.php in Claroline before 1.8.6 allows remote authenticated administrators to inject arbitrary web script or HTML via the sort parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 3.5 | Low | 2017-01-07 | 2008-09-05 | View | |
57114 | CVE-2007-5026 | dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 1614 of 17672, showing 5 records out of 88360 total, starting on record 8066, ending on 8070