NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53502 | CVE-2007-1304 | Multiple SQL injection vulnerabilities in add2.php in Sava"s Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
53758 | CVE-2007-1574 | CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 5 | Medium | 2017-01-07 | 2008-11-13 | View | |
54014 | CVE-2007-1842 | Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
54270 | CVE-2007-2100 | FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb. | 2 | 10 | High | 2017-01-07 | 2008-09-05 | View | |
54526 | CVE-2007-2359 | Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string. | 2 | 7.2 | High | 2017-01-07 | 2011-03-07 | View |
Page 17245 of 17672, showing 5 records out of 88360 total, starting on record 86221, ending on 86225