NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57383 | CVE-2007-5307 | ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter"s hash value, which allows remote attackers to execute arbitrary PHP code by uploading a .php file via externe/swfupload/upload.php. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in ELSEIF CMS. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
57639 | CVE-2007-5574 | PHP remote file inclusion vulnerability in djpage.php in PHPDJ 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
59687 | CVE-2006-0964 | Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View | |
61223 | CVE-2006-2528 | PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
61479 | CVE-2006-2794 | Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View |
Page 266 of 17672, showing 5 records out of 88360 total, starting on record 1326, ending on 1330