NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56099 | CVE-2007-3963 | Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193. | 2 | 9.3 | High | 2017-01-07 | 2008-09-05 | View | |
58403 | CVE-2007-6408 | IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
59939 | CVE-2006-1225 | CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
62499 | CVE-2006-3831 | The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with insufficient access control, which allows remote attackers to obtain sensitive information by downloading a backup file. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63267 | CVE-2006-4634 | Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 242 of 17672, showing 5 records out of 88360 total, starting on record 1206, ending on 1210