NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56193 | CVE-2007-4062 | The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability. | 2 | 7.8 | High | 2017-01-07 | 2008-09-05 | View | |
58241 | CVE-2007-6238 | Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories with actionable information. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. However, the organization has stated that this is different than CVE-2007-6166. | 2 | 10 | High | 2017-01-07 | 2008-09-05 | View | |
58497 | CVE-2007-6502 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects, which trigger a response with the setup directory pathname in the HTML source; and (3) might allow remote attackers to obtain sensitive information via a request for /admin/forum/, which reveals the path in an error message when a forum is not found. | 2 | 5.5 | Medium | 2017-01-07 | 2008-09-05 | View | |
60289 | CVE-2006-1581 | Directory traversal vulnerability in index.php in Blank"N"Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
60801 | CVE-2006-2096 | plug.php in Land Down Under (LDU) 802 and earlier allows remote attackers to obtain sensitive information via an invalid (1) month or (2) year parameter, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 862 of 17672, showing 5 records out of 88360 total, starting on record 4306, ending on 4310