NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57943 | CVE-2007-5918 | Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the SiteTitleName field as an arbitrary user via a modified uname value in an edit action to modules.php. | 2 | 6 | Medium | 2017-01-07 | 2008-09-05 | View | |
58455 | CVE-2007-6460 | Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CVE-2007-6459. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
59735 | CVE-2006-1012 | SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60247 | CVE-2006-1539 | Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62295 | CVE-2006-3621 | SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 556 of 17672, showing 5 records out of 88360 total, starting on record 2776, ending on 2780