NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 53779 | CVE-2007-1595 | The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows remote attackers to execute arbitrary extensions and have an unknown impact by specifying an invalid extension in a certain form. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
| 54035 | CVE-2007-1864 | Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors. | 2 | 7.5 | High | 2017-01-07 | 2012-10-30 | View | |
| 55059 | CVE-2007-2899 | Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action. | 2 | 7.5 | High | 2017-01-07 | 2009-01-22 | View | |
| 55571 | CVE-2007-3419 | The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat.dat, (6) states.dat, and (7) ages.dat files before saving profile settings of members, which has unknown impact and remote attack vectors. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56339 | CVE-2007-4208 | SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View |
Page 2160 of 17672, showing 5 records out of 88360 total, starting on record 10796, ending on 10800