NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 57518 | CVE-2007-5453 | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by (1) admin.php, (2) click.php, (3) download.php, and unspecified other files, as demonstrated by modifying _options through a backup restore action in admin.php. | 2 | 8.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 58030 | CVE-2007-6006 | TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors. | 2 | 10 | High | 2017-01-07 | 2008-11-15 | View | |
| 58542 | CVE-2007-6547 | RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 52911 | CVE-2007-0689 | MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 55471 | CVE-2007-3319 | The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept communications. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View |
Page 2465 of 17672, showing 5 records out of 88360 total, starting on record 12321, ending on 12325