NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55144  CVE-2007-2985  Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator"s username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.    10  High  2017-01-07  2008-11-15  View
56424  CVE-2007-4296  Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors.    7.5  High  2017-01-07  2011-03-07  View
56680  CVE-2007-4560  clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."    7.6  High  2017-01-07  2011-03-07  View
56936  CVE-2007-4825  Directory traversal vulnerability in PHP 5.2.4 and earlier allows attackers to bypass open_basedir restrictions and possibly execute arbitrary code via a .. (dot dot) in the dl function.    7.5  High  2017-01-07  2009-02-05  View
57448  CVE-2007-5383  The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a "/" (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues.    10  High  2017-01-07  2008-10-11  View

Page 3138 of 17672, showing 5 records out of 88360 total, starting on record 15686, ending on 15690

Actions