NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52311  CVE-2007-0079  rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.    7.8  High  2017-01-07  2008-11-15  View
52567  CVE-2007-0340  SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execute arbitrary SQL commands via the board[styleid] parameter to index.php.    7.5  High  2017-01-07  2011-03-07  View
52823  CVE-2007-0601  common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays.    7.5  High  2017-01-07  2008-11-13  View
53079  CVE-2007-0863  ** DISPUTED ** PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php.    10  High  2017-01-07  2008-11-15  View
53591  CVE-2007-1407  Unspecified vulnerability in OpenSolution Quick.Cart before 2.1 has unknown impact and attack vectors, related to a "low critical exploit."    7.5  High  2017-01-07  2008-09-05  View

Page 2675 of 17672, showing 5 records out of 88360 total, starting on record 13371, ending on 13375

Actions