NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53996  CVE-2007-1824  Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the "." character.    5.1  Medium  2017-01-07  2012-11-05  View
54252  CVE-2007-2082  Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.    6.5  Medium  2017-01-07  2008-11-13  View
54764  CVE-2007-2600  Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php.    6.8  Medium  2017-01-07  2012-11-05  View
55020  CVE-2007-2860  user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.    6.5  Medium  2017-01-07  2012-10-30  View
55276  CVE-2007-3122  The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR.    Medium  2017-01-07  2008-11-15  View

Page 16980 of 17672, showing 5 records out of 88360 total, starting on record 84896, ending on 84900

Actions