NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53758 | CVE-2007-1574 | CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 5 | Medium | 2017-01-07 | 2008-11-13 | View | |
54014 | CVE-2007-1842 | Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
54270 | CVE-2007-2100 | FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb. | 2 | 10 | High | 2017-01-07 | 2008-09-05 | View | |
54526 | CVE-2007-2359 | Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string. | 2 | 7.2 | High | 2017-01-07 | 2011-03-07 | View | |
54782 | CVE-2007-2618 | CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS." | 2 | 5.1 | Medium | 2017-01-07 | 2012-10-30 | View |
Page 17596 of 17672, showing 5 records out of 88360 total, starting on record 87976, ending on 87980