NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 55156 | CVE-2007-2997 | ** DISPUTED ** Multiple SQL injection vulnerabilities in cgi-bin/reorder2.asp in SalesCart Shopping Cart allow remote attackers to execute arbitrary SQL commands via the password field and other unspecified vectors. NOTE: the vendor disputes this issue, stating "We were able to reproduce this sql injection on an old out-of-date demo on the website but not on the released product." | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56948 | CVE-2007-4837 | SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56437 | CVE-2007-4312 | SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a "print articles" action. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 57717 | CVE-2007-5654 | LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection." | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 53110 | CVE-2007-0894 | MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 2395 of 17672, showing 5 records out of 88360 total, starting on record 11971, ending on 11975