NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 53329 | CVE-2007-1122 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was fixed in 1.01. NOTE: some of these details are obtained from third party information. | 2 | 6.4 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 53585 | CVE-2007-1401 | Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function. | 2 | 6.9 | Medium | 2017-01-07 | 2008-09-05 | View | |
| 54097 | CVE-2007-1927 | Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-13 | View | |
| 54865 | CVE-2007-2701 | The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a username and password, or when the connection URL is not defined, allows remote attackers to bypass the security access policy and "send unauthorized messages to a protected queue." | 2 | 4.6 | Medium | 2017-01-07 | 2011-03-07 | View | |
| 55121 | CVE-2007-2962 | Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-15 | View |
Page 2929 of 17672, showing 5 records out of 88360 total, starting on record 14641, ending on 14645