NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58407 | CVE-2007-6412 | Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attackers to inject arbitrary PHP code via an editcomments action. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 58663 | CVE-2007-6668 | admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 58919 | CVE-2006-0179 | The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59175 | CVE-2006-0437 | Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59431 | CVE-2006-0700 | imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions. | 2 | 5 | Medium | 2016-12-20 | 2011-10-17 | View |
Page 2710 of 17672, showing 5 records out of 88360 total, starting on record 13546, ending on 13550