NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58266 | CVE-2007-6270 | Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58522 | CVE-2007-6527 | uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type. | 2 | 5.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 52379 | CVE-2007-0147 | Cuyahoga before 1.0.1 installs the FCKEditor component with an incorrect deny statement in a Web.config file, which allows remote attackers to upload files when these privileges were intended only for the Administrator and Editor roles. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 53147 | CVE-2007-0932 | The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 54939 | CVE-2007-2775 | AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php. | 2 | 10 | High | 2017-01-07 | 2008-11-15 | View |
Page 2439 of 17672, showing 5 records out of 88360 total, starting on record 12191, ending on 12195