NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58133 | CVE-2007-6126 | Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the year parameter to (1) xml/index.php; or (2) the year parameter to view.page.inc.php, which is reachable through a view action to the top-level index.php. | 2 | 4.3 | Medium | 2017-01-07 | 2011-03-07 | View | |
58389 | CVE-2007-6394 | SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
58645 | CVE-2007-6650 | Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file. | 2 | 7.5 | High | 2017-01-07 | 2009-09-15 | View | |
58901 | CVE-2006-0161 | Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
59157 | CVE-2006-0419 | BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 1839 of 17672, showing 5 records out of 88360 total, starting on record 9191, ending on 9195