NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57862 | CVE-2007-5811 | ** DISPUTED ** Directory traversal vulnerability in PageTraiteDownload.php in phpMyConferences 8.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter. NOTE: this issue is disputed for 8.0.2 by a reliable third party, who notes that the PHP code is syntactically incorrect and cannot be executed. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
58118 | CVE-2007-6111 | Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector. | 2 | 7.1 | High | 2017-01-07 | 2011-03-07 | View | |
58374 | CVE-2007-6379 | BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
58630 | CVE-2007-6635 | FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in cleartext in a database, which might allow context-dependent attackers to obtain the password via unspecified database access. | 2 | 6.4 | Medium | 2017-01-07 | 2008-09-05 | View | |
58886 | CVE-2006-0146 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-06-14 | View |
Page 415 of 17672, showing 5 records out of 88360 total, starting on record 2071, ending on 2075