NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55025  CVE-2007-2865  Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.    9.3  High  2017-01-07  2012-10-30  View
55281  CVE-2007-3127  content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "";" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.    Medium  2017-01-07  2013-08-21  View
55537  CVE-2007-3385  Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the " character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.    4.3  Medium  2017-01-07  2011-04-20  View
55793  CVE-2007-3643  admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions.    10  High  2017-01-07  2008-11-15  View
56049  CVE-2007-3911  Multiple heap-based buffer overflows in (1) clsscheduler.exe (aka scheduler client) and (2) srvscheduler.exe (aka scheduler server) in BakBone NetVault Reporter 3.5 before Update4 allow remote attackers to execute arbitrary code via long filename arguments in HTTP requests.    10  High  2017-01-07  2011-03-07  View

Page 16820 of 17672, showing 5 records out of 88360 total, starting on record 84096, ending on 84100

Actions