NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
53248 | CVE-2007-1040 | Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include arbitrary files or obtain sensitive information via a .. (dot dot) in the xnews-template parameter. | 2 | 7.5 | High | 2017-01-07 | 2011-03-07 | View | |
53504 | CVE-2007-1306 | Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference. | 2 | 7.8 | High | 2017-01-07 | 2011-03-07 | View | |
53760 | CVE-2007-1576 | Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Search (only Gecko engine driven Browsers), and (5) Notes modules; the (6) Mail summary page; and unspecified other files. | 2 | 4.3 | Medium | 2017-01-07 | 2016-09-06 | View | |
54016 | CVE-2007-1844 | Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
54272 | CVE-2007-2102 | Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vector than CVE-2006-6087. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-13 | View |
Page 51 of 17672, showing 5 records out of 88360 total, starting on record 251, ending on 255