NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56160  CVE-2007-4028  Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2008-11-15  View
56672  CVE-2007-4552  SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.    7.5  High  2017-01-07  2008-11-15  View
56928  CVE-2007-4817  Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attackers to upload and execute arbitrary PHP code via an upload action specifying a filename with a double extension such as .php.jpg, which creates an accessible file under img_original/.    7.5  High  2017-01-07  2011-03-07  View
57184  CVE-2007-5101  ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local users to gain privileges.    7.2  High  2017-01-07  2008-11-15  View
57696  CVE-2007-5633  Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to Devicespeedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR.    7.2  High  2017-01-07  2008-11-15  View

Page 2925 of 17672, showing 5 records out of 88360 total, starting on record 14621, ending on 14625

Actions