NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55574  CVE-2007-3422  The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.    7.5  High  2017-01-07  2008-11-15  View
57878  CVE-2007-5827  iSCSI Enterprise Target (iscsitarget) 0.4.15 uses weak permissions for /etc/ietd.conf, which allows local users to obtain passwords.    2.1  Low  2017-01-07  2008-11-15  View
58390  CVE-2007-6395  Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.    Medium  2017-01-07  2008-11-15  View
58646  CVE-2007-6651  Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter.    Medium  2017-01-07  2008-11-15  View
53015  CVE-2007-0798  Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp.    4.3  Medium  2017-01-07  2008-11-15  View

Page 2302 of 17672, showing 5 records out of 88360 total, starting on record 11506, ending on 11510

Actions