NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53096  CVE-2007-0880  Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.    7.8  High  2017-01-07  2008-11-15  View
53608  CVE-2007-1424  Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2008-11-15  View
54888  CVE-2007-2724  Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web script or HTML via the user parameter.    4.3  Medium  2017-01-07  2008-11-15  View
55144  CVE-2007-2985  Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator"s username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.    10  High  2017-01-07  2008-11-15  View
58216  CVE-2007-6213  Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path parameters.    Medium  2017-01-07  2008-11-15  View

Page 2384 of 17672, showing 5 records out of 88360 total, starting on record 11916, ending on 11920

Actions