NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56602  CVE-2007-4479  Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.    4.3  Medium  2017-01-07  2008-11-15  View
56858  CVE-2007-4741  Cross-site scripting (XSS) vulnerability in admin/adminusers.php in Claroline before 1.8.6 allows remote authenticated administrators to inject arbitrary web script or HTML via the sort parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    3.5  Low  2017-01-07  2008-09-05  View
57114  CVE-2007-5026  dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb.    Medium  2017-01-07  2008-11-15  View
57370  CVE-2007-5294  PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter.    6.8  Medium  2017-01-07  2011-03-07  View
57626  CVE-2007-5561  Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, allows remote attackers to execute arbitrary code via format string specifiers in the URI in an HTTP request to port 6003, aka Oracle reference number 6296175. NOTE: this might be the same issue as CVE-2007-0282 or CVE-2007-0280, but there are insufficient details to be sure.    10  High  2017-01-07  2008-09-05  View

Page 1826 of 17672, showing 5 records out of 88360 total, starting on record 9126, ending on 9130

Actions