NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52731 | CVE-2007-0507 | SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles. | 2 | 6 | Medium | 2017-01-07 | 2011-03-07 | View | |
52987 | CVE-2007-0767 | Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-07 | 2013-07-04 | View | |
53755 | CVE-2007-1571 | PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
54523 | CVE-2007-2356 | Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file. | 2 | 6.8 | Medium | 2017-01-07 | 2011-07-28 | View | |
55291 | CVE-2007-3137 | Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect. | 2 | 4.3 | Medium | 2017-01-07 | 2012-10-30 | View |
Page 17528 of 17672, showing 5 records out of 88360 total, starting on record 87636, ending on 87640