NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52478  CVE-2007-0250  index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a " (quote) character in the o parameter, which forces a SQL error.    Medium  2017-01-07  2008-11-15  View
53246  CVE-2007-1038  Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing ";" (semicolon) characters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    Medium  2017-01-07  2011-03-07  View
53502  CVE-2007-1304  Multiple SQL injection vulnerabilities in add2.php in Sava"s Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.    6.8  Medium  2017-01-07  2008-09-05  View
53758  CVE-2007-1574  CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    Medium  2017-01-07  2008-11-13  View
54782  CVE-2007-2618  CRLF injection vulnerability in index.php in Drake CMS 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the lang parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."    5.1  Medium  2017-01-07  2012-10-30  View

Page 17633 of 17672, showing 5 records out of 88360 total, starting on record 88161, ending on 88165

Actions