NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55147  CVE-2007-2988  A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a request to admin/create_engine.php followed by a request to admin/generate_tabs.php.    7.5  High  2017-01-07  2008-11-15  View
56683  CVE-2007-4563  Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user"s group permissions to logical J2EE server processes, which allows local users to gain privileges.    4.4  Medium  2017-01-07  2008-11-15  View
57195  CVE-2007-5112  Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers that support remembered (auto-completed) passwords.    4.3  Medium  2017-01-07  2008-11-15  View
52332  CVE-2007-0100  The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.    10  High  2017-01-07  2008-11-15  View
52844  CVE-2007-0622  Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    Medium  2017-01-07  2008-11-15  View

Page 2387 of 17672, showing 5 records out of 88360 total, starting on record 11931, ending on 11935

Actions