NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53771  CVE-2007-1587  templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by specifying the program name in the qshapeLocation parameter.    10  High  2017-01-07  2012-11-05  View
54027  CVE-2007-1855  Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) smarty_compile_path, (3) get_plugin_filepath, (4) smarty_dir, and (5) filename parameters. NOTE: this issue might be related to CVE-2006-7105.    7.5  High  2017-01-07  2008-11-13  View
54283  CVE-2007-2113  SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Database 10.1.0.5 allows remote authenticated users to execute arbitrary SQL commands via unknown vectors, aka DB07. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB07 is actually for multiple issues.    7.5  High  2017-01-07  2012-10-22  View
54539  CVE-2007-2372  admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.    10  High  2017-01-07  2008-09-05  View
54795  CVE-2007-2631  Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. NOTE: this issue might overlap CVE-2007-2589 or CVE-2002-1648.    7.5  High  2017-01-07  2008-11-15  View

Page 666 of 17672, showing 5 records out of 88360 total, starting on record 3326, ending on 3330

Actions