NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58407  CVE-2007-6412  Direct static code injection vulnerability in wiki/index.php in Bitweaver 2.0.0 and earlier, when comments are enabled, allows remote attackers to inject arbitrary PHP code via an editcomments action.    6.8  Medium  2017-01-07  2008-11-15  View
58663  CVE-2007-6668  admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file.    7.5  High  2017-01-07  2008-11-15  View
58919  CVE-2006-0179  The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.    Medium  2016-12-20  2011-03-07  View
59175  CVE-2006-0437  Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.    4.3  Medium  2016-12-20  2011-03-07  View
59431  CVE-2006-0700  imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.    Medium  2016-12-20  2011-10-17  View

Page 2710 of 17672, showing 5 records out of 88360 total, starting on record 13546, ending on 13550

Actions