NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
57126  CVE-2007-5038  The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote attackers to bypass intended restrictions on account creation.    7.5  High  2017-01-07  2011-03-07  View
58150  CVE-2007-6143  SQL injection vulnerability in default.asp (aka the Login Page) in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.    7.5  High  2017-01-07  2011-03-07  View
60198  CVE-2006-1489  Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters.    7.5  High  2016-12-20  2008-11-03  View
60454  CVE-2006-1749  PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well.    7.5  High  2016-12-20  2011-08-23  View
60710  CVE-2006-2005  Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.    7.5  High  2016-12-20  2008-09-05  View

Page 2371 of 17672, showing 5 records out of 88360 total, starting on record 11851, ending on 11855

Actions