NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53335  CVE-2007-1128  shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages.    Medium  2017-01-07  2008-11-15  View
57175  CVE-2007-5092  Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php.    6.8  Medium  2017-01-07  2008-11-15  View
58199  CVE-2007-6196  Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter.    4.3  Medium  2017-01-07  2008-11-15  View
52312  CVE-2007-0080  ** DISPUTED ** Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute.    6.6  Medium  2017-01-07  2008-11-15  View
56664  CVE-2007-4544  Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).    4.3  Medium  2017-01-07  2008-11-15  View

Page 2367 of 17672, showing 5 records out of 88360 total, starting on record 11831, ending on 11835

Actions