NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55071  CVE-2007-2911  SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC["search"]["datelineafter"] variable), a related issue to CVE-2007-1573.    8.5  High  2017-01-07  2008-11-13  View
52769  CVE-2007-0545  Maxtricity Tagger 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for tagger.mdb.    7.8  High  2017-01-07  2008-11-13  View
54305  CVE-2007-2135  The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.    7.8  High  2017-01-07  2008-11-13  View
52770  CVE-2007-0546  Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.    7.8  High  2017-01-07  2008-11-13  View
54818  CVE-2007-2654  xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.    4.4  Medium  2017-01-07  2008-11-13  View

Page 2230 of 17672, showing 5 records out of 88360 total, starting on record 11146, ending on 11150

Actions