NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53807 | CVE-2007-1623 | Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7) fc_normal, and (8) ff_normal parameters to welcome_admin.php; and possibly unspecified other parameters and files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
55343 | CVE-2007-3189 | Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
56623 | CVE-2007-4500 | Unspecified vulnerability in TunnelRunner in SSHKeychain before 0.8.2 beta, and possibly later versions, allows local users to gain privileges via unspecified vectors. | 2 | 6.9 | Medium | 2017-01-07 | 2008-09-05 | View | |
59183 | CVE-2006-0445 | index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "", which will display the full path of uploader.php. NOTE: this might be the result of a file inclusion vulnerability. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View | |
59695 | CVE-2006-0972 | SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 16287 of 17672, showing 5 records out of 88360 total, starting on record 81431, ending on 81435