NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57979 | CVE-2007-5954 | Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
58235 | CVE-2007-6232 | Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
58491 | CVE-2007-6496 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a related issue to CVE-2005-1654. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
59515 | CVE-2006-0785 | Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) "/" (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
60283 | CVE-2006-1575 | Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 822 of 17672, showing 5 records out of 88360 total, starting on record 4106, ending on 4110