NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53787 | CVE-2007-1603 | admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
55835 | CVE-2007-3686 | CRLF injection vulnerability in db.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary HTTP headers and data via CRLF sequences in the HTTP_REFERER parameter. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
60187 | CVE-2006-1478 | Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64283 | CVE-2006-5708 | Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64795 | CVE-2006-6234 | Multiple SQL injection vulnerabilities in the Content module in PHP-Nuke 6.0, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in a list_pages_categories action or (2) the pid parameter in a showpage action. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 16176 of 17672, showing 5 records out of 88360 total, starting on record 80876, ending on 80880