NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58133  CVE-2007-6126  Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php.    4.3  Medium  2017-01-07  2011-03-07  View
58389  CVE-2007-6394  SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action.    7.5  High  2017-01-07  2011-03-07  View
58645  CVE-2007-6650  Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file.    7.5  High  2017-01-07  2009-09-15  View
58901  CVE-2006-0161  Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.    4.6  Medium  2016-12-20  2011-03-07  View
59157  CVE-2006-0419  BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections.    6.4  Medium  2016-12-20  2008-09-05  View

Page 1839 of 17672, showing 5 records out of 88360 total, starting on record 9191, ending on 9195

Actions