NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53549  CVE-2007-1364  DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.    6.4  Medium  2017-01-07  2008-09-05  View
58669  CVE-2007-6674  Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.    4.3  Medium  2017-01-07  2008-09-05  View
59693  CVE-2006-0970  PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.    7.5  High  2016-12-20  2008-09-05  View
59949  CVE-2006-1235  Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir.    Medium  2016-12-20  2008-09-05  View
60205  CVE-2006-1496  Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.    4.3  Medium  2016-12-20  2008-09-05  View

Page 300 of 17672, showing 5 records out of 88360 total, starting on record 1496, ending on 1500

Actions