NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53015  CVE-2007-0798  Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp.    4.3  Medium  2017-01-07  2008-11-15  View
53271  CVE-2007-1063  The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.    10  High  2017-01-07  2011-03-07  View
53527  CVE-2007-1341  include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.    Medium  2017-01-07  2008-11-13  View
53783  CVE-2007-1599  wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirect_to parameter.    6.5  Medium  2017-01-07  2008-09-05  View
54039  CVE-2007-1868  The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.    10  High  2017-01-07  2012-11-05  View

Page 1620 of 17672, showing 5 records out of 88360 total, starting on record 8096, ending on 8100

Actions