NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53502  CVE-2007-1304  Multiple SQL injection vulnerabilities in add2.php in Sava"s Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.    6.8  Medium  2017-01-07  2008-09-05  View
53758  CVE-2007-1574  CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    Medium  2017-01-07  2008-11-13  View
54014  CVE-2007-1842  Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.    7.5  High  2017-01-07  2011-03-07  View
54270  CVE-2007-2100  FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb.    10  High  2017-01-07  2008-09-05  View
54526  CVE-2007-2359  Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.    7.2  High  2017-01-07  2011-03-07  View

Page 17245 of 17672, showing 5 records out of 88360 total, starting on record 86221, ending on 86225

Actions