NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 55144 | CVE-2007-2985 | Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator"s username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php. | 2 | 10 | High | 2017-01-07 | 2008-11-15 | View | |
| 56424 | CVE-2007-4296 | Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
| 56680 | CVE-2007-4560 | clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail." | 2 | 7.6 | High | 2017-01-07 | 2011-03-07 | View | |
| 56936 | CVE-2007-4825 | Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function. | 2 | 7.5 | High | 2017-01-07 | 2009-02-05 | View | |
| 57448 | CVE-2007-5383 | The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a "/" (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues. | 2 | 10 | High | 2017-01-07 | 2008-10-11 | View |
Page 3138 of 17672, showing 5 records out of 88360 total, starting on record 15686, ending on 15690