NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54067  CVE-2007-1897  SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.    6.5  Medium  2017-01-07  2011-08-05  View
54323  CVE-2007-2153  Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.    6.8  Medium  2017-01-07  2008-09-05  View
54579  CVE-2007-2412  ** DISPUTED ** Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive information via a .. (dot dot) in the a[filepath] parameter. NOTE: a third party has disputed this issue because the a array is populated by a database query before use.    7.8  High  2017-01-07  2008-09-05  View
54835  CVE-2007-2671  Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.    7.1  High  2017-01-07  2012-11-05  View
55091  CVE-2007-2932  Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.    4.3  Medium  2017-01-07  2008-11-15  View

Page 3118 of 17672, showing 5 records out of 88360 total, starting on record 15586, ending on 15590

Actions