NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57053 | CVE-2007-4963 | Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of space characters in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged with a separate directory traversal vulnerability to trick a careful user into overwriting arbitrary files. | 2 | 9.3 | High | 2017-01-07 | 2008-11-15 | View | |
57309 | CVE-2007-5233 | SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
58333 | CVE-2007-6338 | SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2014-03-03 | View | |
59357 | CVE-2006-0626 | SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59613 | CVE-2006-0884 | The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail. | 2 | 9.3 | High | 2016-12-20 | 2011-05-25 | View |
Page 16398 of 17672, showing 5 records out of 88360 total, starting on record 81986, ending on 81990