NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52386  CVE-2007-0154  Webulas stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/db.mdb.    7.5  High  2017-01-07  2008-11-15  View
55458  CVE-2007-3306  PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.    7.5  High  2017-01-07  2008-11-15  View
56994  CVE-2007-4904  RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.    4.3  Medium  2017-01-07  2008-11-15  View
57506  CVE-2007-5441  CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.    6.5  Medium  2017-01-07  2008-11-15  View
58018  CVE-2007-5994  PHP remote file inclusion vulnerability in check_noimage.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the config[path_src_include] parameter.    6.8  Medium  2017-01-07  2008-11-15  View

Page 2449 of 17672, showing 5 records out of 88360 total, starting on record 12241, ending on 12245

Actions