NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55173 | CVE-2007-3014 | Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype). | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
55941 | CVE-2007-3796 | The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables. | 2 | 7.6 | High | 2017-01-07 | 2008-09-05 | View | |
57221 | CVE-2007-5138 | PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
57733 | CVE-2007-5674 | Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
60549 | CVE-2006-1844 | The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges. | 2 | 2.1 | Low | 2016-12-20 | 2008-09-05 | View |
Page 16869 of 17672, showing 5 records out of 88360 total, starting on record 84341, ending on 84345