NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
55088 | CVE-2007-2929 | The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code. | 2 | 5.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
55344 | CVE-2007-3190 | Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
55600 | CVE-2007-3448 | Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
55856 | CVE-2007-3707 | Directory traversal vulnerability in index.php in CodeIgniter 1.5.3 before 20070628, when enable_query_strings is true, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter. | 2 | 5 | Medium | 2017-01-07 | 2012-10-30 | View | |
56368 | CVE-2007-4239 | Cross-site scripting (XSS) vulnerability in user/forgotPassStep2.jsp in the admin interface in C-SAM oneWallet 210_07062007;1.0 allows remote attackers to inject arbitrary web script or HTML via the loginID parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 1760 of 17672, showing 5 records out of 88360 total, starting on record 8796, ending on 8800