NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53349  CVE-2007-1142  Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the link_parameters parameter in (1) news.php and (2) n_layouts.php.    4.3  Medium  2017-01-07  2009-02-26  View
53350  CVE-2007-1143  Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.    7.8  High  2017-01-07  2009-02-26  View
53359  CVE-2007-1152  Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) act or (2) pid parameter to the top-level URI (index.php), or the (3) action parameter to admin/index.php. NOTE: some of these details are obtained from third party information.    Medium  2017-01-07  2009-02-26  View
4720  CVE-2008-4931  Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.    4.3  Medium  2017-01-03  2009-02-26  View
4721  CVE-2008-4932  webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.    High  2017-01-03  2009-02-26  View

Page 2792 of 17672, showing 5 records out of 88360 total, starting on record 13956, ending on 13960

Actions