NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58399 | CVE-2007-6404 | Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to read arbitrary files via a .. (dot dot backslash) in the URI. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
58655 | CVE-2007-6660 | 2z project 0.9.6.1 allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid template or (2) a request to the default URI with certain year and month parameters, which reveals the path in various error messages. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
58911 | CVE-2006-0171 | PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
59167 | CVE-2006-0429 | BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions. | 2 | 2.1 | Low | 2016-12-20 | 2011-03-07 | View | |
59423 | CVE-2006-0692 | Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 1919 of 17672, showing 5 records out of 88360 total, starting on record 9591, ending on 9595