NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55025 | CVE-2007-2865 | Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. | 2 | 9.3 | High | 2017-01-07 | 2012-10-30 | View | |
55281 | CVE-2007-3127 | content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "";" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message. | 2 | 5 | Medium | 2017-01-07 | 2013-08-21 | View | |
55537 | CVE-2007-3385 | Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the " character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. | 2 | 4.3 | Medium | 2017-01-07 | 2011-04-20 | View | |
55793 | CVE-2007-3643 | admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions. | 2 | 10 | High | 2017-01-07 | 2008-11-15 | View | |
56049 | CVE-2007-3911 | Multiple heap-based buffer overflows in (1) clsscheduler.exe (aka scheduler client) and (2) srvscheduler.exe (aka scheduler server) in BakBone NetVault Reporter 3.5 before Update4 allow remote attackers to execute arbitrary code via long filename arguments in HTTP requests. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View |
Page 16820 of 17672, showing 5 records out of 88360 total, starting on record 84096, ending on 84100