NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53549 | CVE-2007-1364 | DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php. | 2 | 6.4 | Medium | 2017-01-07 | 2008-09-05 | View | |
58669 | CVE-2007-6674 | Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
59693 | CVE-2006-0970 | PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
59949 | CVE-2006-1235 | Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
60205 | CVE-2006-1496 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 300 of 17672, showing 5 records out of 88360 total, starting on record 1496, ending on 1500