NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57221 | CVE-2007-5138 | PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the view parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
57733 | CVE-2007-5674 | Directory traversal vulnerability in index.php in InstaGuide Weather (aka Weather for PHP) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PageName parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
60549 | CVE-2006-1844 | The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges. | 2 | 2.1 | Low | 2016-12-20 | 2008-09-05 | View | |
61061 | CVE-2006-2359 | Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
62597 | CVE-2006-3939 | ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform administrative activities without authentication in (1) filter.php, which permits changing the Extensions Mode file type; (2) access.php, which permits changing the Protection Method; (3) edituser.php, which permits adding upload capabilities to user accounts; (4) settings.php, which permits changing the admin information; and (5) index.php, which permits uploading of arbitrary files. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 892 of 17672, showing 5 records out of 88360 total, starting on record 4456, ending on 4460