NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 53335 | CVE-2007-1128 | shopkitplus allows remote attackers to obtain sensitive information via a request to (1) events.php with a curmonth[]=01 query string or (2) enc/stylecss.php with a changetheme[]= query string, which reveals the path in various error messages. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57175 | CVE-2007-5092 | Directory traversal vulnerability in index.php in the Dance Music module for phpNuke, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an ACCEPT_FILE array parameter to modules.php. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58199 | CVE-2007-6196 | Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 52312 | CVE-2007-0080 | ** DISPUTED ** Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute. | 2 | 6.6 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 56664 | CVE-2007-4544 | Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field). | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 2367 of 17672, showing 5 records out of 88360 total, starting on record 11831, ending on 11835