NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52914 | CVE-2007-0692 | DGNews 2.1 allows remote attackers to obtain sensitive information via a fullnews request to news.php with an invalid newsid parameter, and other unspecified vectors, which reveal the path in various error messages. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
56242 | CVE-2007-4111 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
56498 | CVE-2007-4373 | The server in Babo Violent 2 2.08.00 and earlier does not properly implement password protection, which might allow remote attackers to bypass authentication by reconnecting after a connection closes. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
57522 | CVE-2007-5457 | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) install.joomla_flash_uploader.php and (2) uninstall.joomla_flash_uploader.php. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
59570 | CVE-2006-0840 | manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a " (quote) character, which allows remote attackers to trigger a SQL error that may be repeatedly reported to a user who makes subsequent web accesses with the MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as vector 2 in CVE-2005-4519. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17168 of 17672, showing 5 records out of 88360 total, starting on record 85836, ending on 85840