NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52019  CVE-2009-4904  article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.    Medium  2017-01-07  2012-11-05  View
52787  CVE-2007-0563  Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS.    4.3  Medium  2017-01-07  2011-03-07  View
53299  CVE-2007-1091  Microsoft Internet Explorer 7 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via onUnload Javascript handlers.    6.8  Medium  2017-01-07  2011-03-07  View
53555  CVE-2007-1370  Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modifying the files. NOTE: this only occurs when safe_mode and open_basedir are disabled; other settings require leverage for other vulnerabilities.    6.2  Medium  2017-01-07  2011-03-07  View
54067  CVE-2007-1897  SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.    6.5  Medium  2017-01-07  2011-08-05  View

Page 1863 of 17672, showing 5 records out of 88360 total, starting on record 9311, ending on 9315

Actions