NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53996 | CVE-2007-1824 | Buffer overflow in the php_stream_filter_create function in PHP 5 before 5.2.1 allows remote attackers to cause a denial of service (application crash) via a php://filter/ URL that has a name ending in the "." character. | 2 | 5.1 | Medium | 2017-01-07 | 2012-11-05 | View | |
54252 | CVE-2007-2082 | Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers. | 2 | 6.5 | Medium | 2017-01-07 | 2008-11-13 | View | |
54764 | CVE-2007-2600 | Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) catFile parameter to (a) browseCat.php or (b) browseSubCat.php; the (2) id parameter to (c) openTutorial.php, (d) topFrame.php, or (e) admin/editListing.php; or the (3) search parameter to search.php. | 2 | 6.8 | Medium | 2017-01-07 | 2012-11-05 | View | |
55020 | CVE-2007-2860 | user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action. | 2 | 6.5 | Medium | 2017-01-07 | 2012-10-30 | View | |
55276 | CVE-2007-3122 | The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 16980 of 17672, showing 5 records out of 88360 total, starting on record 84896, ending on 84900