NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 56729 | CVE-2007-4609 | eyeOS uses predictable checksum values in the checknum parameter for access control, which allows remote attackers to register many accounts via doCreateUser actions, add many eyeBoard messages via addMsg actions, and cause a denial of service or conduct certain unauthorized activities, by guessing valid parameter values. | 2 | 6.4 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57241 | CVE-2007-5158 | The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upload field, a related issue to CVE-2007-3511. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 57497 | CVE-2007-5432 | Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 58009 | CVE-2007-5985 | Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58265 | CVE-2007-6269 | Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View |
Page 2437 of 17672, showing 5 records out of 88360 total, starting on record 12181, ending on 12185