NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54539  CVE-2007-2372  admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.    10  High  2017-01-07  2008-09-05  View
54795  CVE-2007-2631  Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. NOTE: this issue might overlap CVE-2007-2589 or CVE-2002-1648.    7.5  High  2017-01-07  2008-11-15  View
55051  CVE-2007-2891  Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.    7.5  High  2017-01-07  2011-03-07  View
55307  CVE-2007-3153  The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.    Medium  2017-01-07  2012-10-30  View
55563  CVE-2007-3411  SQL injection vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the image_id parameter.    7.5  High  2017-01-07  2008-11-15  View

Page 2914 of 17672, showing 5 records out of 88360 total, starting on record 14566, ending on 14570

Actions