NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
54641 | CVE-2007-2474 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
55153 | CVE-2007-2994 | SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a fullnews action, a different vector than CVE-2007-0693. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
57713 | CVE-2007-5650 | Directory traversal vulnerability in system.php in ReloadCMS 1.2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
58225 | CVE-2007-6222 | The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, which allows remote authenticated users with the LIMITTOCUSTOMERS privilege to bypass intended access restrictions and edit non-active user settings. NOTE: some of these details are obtained from third party information. | 2 | 6.5 | Medium | 2017-01-07 | 2008-09-05 | View | |
58481 | CVE-2007-6486 | Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 16723 of 17672, showing 5 records out of 88360 total, starting on record 83611, ending on 83615