NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
52828 | CVE-2007-0606 | w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php, which expects a string, and (2) certain parameters to delete_forum.php, which displays the path name in the resulting error message. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
53596 | CVE-2007-1412 | The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument. | 2 | 7.8 | High | 2017-01-07 | 2008-09-05 | View | |
56668 | CVE-2007-4548 | The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module. | 2 | 10 | High | 2017-01-07 | 2008-09-05 | View | |
59996 | CVE-2006-1282 | CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
61788 | CVE-2006-3108 | Cross-site scripting (XSS) vulnerability in EmailArchitect Email Server 6.1 allows remote attackers to inject arbitrary Javascript via an HTML div tag with a carriage return between the onmouseover attribute and its value, which bypasses the mail filter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 588 of 17672, showing 5 records out of 88360 total, starting on record 2936, ending on 2940