NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
57528  CVE-2007-5463  ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than CVE-2007-5364. NOTE: this can be leveraged for reading certificate or key files if an installation places these files under the web document root.    Medium  2017-01-07  2008-11-15  View
57784  CVE-2007-5727  Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.    4.3  Medium  2017-01-07  2008-11-15  View
58552  CVE-2007-6557  Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.    7.5  High  2017-01-07  2008-11-15  View
52409  CVE-2007-0178  PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.    7.5  High  2017-01-07  2008-11-15  View
54969  CVE-2007-2806  Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters.    5.8  Medium  2017-01-07  2008-11-15  View

Page 2477 of 17672, showing 5 records out of 88360 total, starting on record 12381, ending on 12385

Actions