NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54813 | CVE-2007-2649 | Deutsche Telekom (T-com) Speedport W 700v uses JavaScript delays for invalid authentication attempts to the CGI script, which allows remote attackers to bypass the delays and conduct brute-force attacks via direct calls to the authentication CGI script. | 2 | 7.8 | High | 2017-01-07 | 2008-11-15 | View | |
| 55069 | CVE-2007-2909 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update. | 2 | 3.5 | Low | 2017-01-07 | 2012-11-05 | View | |
| 55325 | CVE-2007-3171 | Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages. | 2 | 5 | Medium | 2017-01-07 | 2012-10-30 | View | |
| 55581 | CVE-2007-3429 | Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allows remote attackers to upload and execute arbitrary PHP code via a filename with a double extension such as .php.jpg. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 55837 | CVE-2007-3688 | Multiple cross-site request forgery (CSRF) vulnerabilities in DotClear 1.2.6 allow remote attackers to perform actions as arbitrary users via the (1) tool_url parameter to ecrire/tools.php and multiple fields on the (2) blogconf, (3) blogroll, (4) ecrire/redacteur.php, and (5) ecrire/user_prefs.php pages. | 2 | 2.6 | Low | 2017-01-07 | 2012-11-05 | View |
Page 2379 of 17672, showing 5 records out of 88360 total, starting on record 11891, ending on 11895