NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52864  CVE-2007-0642  SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.    7.5  High  2017-01-07  2008-09-05  View
53376  CVE-2007-1169  The web interface in Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 accepts logon requests through unencrypted HTTP, which might allow remote attackers to obtain credentials by sniffing the network.    Medium  2017-01-07  2008-09-05  View
56960  CVE-2007-4849  JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enabled, does not properly store permissions during (1) inode creation or (2) ACL setting, which might allow local users to access restricted files or directories after a remount of a filesystem, related to "legacy modes" and an inconsistency between dentry permissions and inode permissions.    4.4  Medium  2017-01-07  2008-09-05  View
58240  CVE-2007-6237  cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.    High  2017-01-07  2008-09-05  View
58496  CVE-2007-6501  Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp.    5.5  Medium  2017-01-07  2008-09-05  View

Page 16832 of 17672, showing 5 records out of 88360 total, starting on record 84156, ending on 84160

Actions