NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 52230 | CVE-2009-5135 | The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2 | 5 | Medium | 2017-01-07 | 2013-05-02 | View | |
| 52486 | CVE-2007-0258 | Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 52742 | CVE-2007-0518 | Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
| 52998 | CVE-2007-0778 | The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache. | 2 | 5.4 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 53254 | CVE-2007-1046 | Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt. | 2 | 5 | Medium | 2017-01-07 | 2013-07-21 | View |
Page 2614 of 17672, showing 5 records out of 88360 total, starting on record 13066, ending on 13070