NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54917 | CVE-2007-2753 | RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 55685 | CVE-2007-3534 | SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56965 | CVE-2007-4863 | SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57477 | CVE-2007-5412 | Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2) allopass-error.php. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 55174 | CVE-2007-3017 | The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp. | 2 | 4 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 2411 of 17672, showing 5 records out of 88360 total, starting on record 12051, ending on 12055