NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
52806  CVE-2007-0582  SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.    7.5  High  2017-01-07  2011-03-07  View
53062  CVE-2007-0845  admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain administrator privileges by obtaining a valid session identifier and setting the uid parameter to 1.    7.5  High  2017-01-07  2011-03-07  View
56390  CVE-2007-4261  EZPhotoSales 1.9.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) a file containing cleartext passwords via a direct request for OnlineViewing/data/galleries.txt, or (2) a file containing username hashes and password hashes via a direct request for OnlineViewing/configuration/config.dat/. NOTE: vector 2 can be leveraged for administrative access because authentication does not require knowledge of cleartext values, but instead uses the username hash in the ConfigLogin parameter and the password hash in the ConfigPassword parameter.    7.5  High  2017-01-07  2012-11-05  View
58182  CVE-2007-6179  Multiple PHP remote file inclusion vulnerabilities in Charray"s CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_library_path parameter to (1) markdown.php and (2) gallery.php in decoder/.    7.5  High  2017-01-07  2008-11-15  View
59206  CVE-2006-0468  CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.    7.5  High  2016-12-20  2011-03-07  View

Page 2732 of 17672, showing 5 records out of 88360 total, starting on record 13656, ending on 13660

Actions