NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55173  CVE-2007-3014  Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).    4.3  Medium  2017-01-07  2008-09-05  View
55941  CVE-2007-3796  The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.    7.6  High  2017-01-07  2008-09-05  View
57221  CVE-2007-5138  PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter.    6.8  Medium  2017-01-07  2008-09-05  View
57733  CVE-2007-5674  Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter.    6.8  Medium  2017-01-07  2008-09-05  View
60549  CVE-2006-1844  The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.    2.1  Low  2016-12-20  2008-09-05  View

Page 16869 of 17672, showing 5 records out of 88360 total, starting on record 84341, ending on 84345

Actions