NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57114 | CVE-2007-5026 | dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
57370 | CVE-2007-5294 | PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2011-03-07 | View | |
57882 | CVE-2007-5831 | Directory traversal vulnerability in fileSystem.do in SSL-Explorer before 0.2.14 allows remote attackers to access arbitrary files via directory traversal sequences in the path parameter. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2017-01-07 | 2012-10-30 | View | |
58394 | CVE-2007-6399 | index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action. | 2 | 6.5 | Medium | 2017-01-07 | 2008-11-15 | View | |
59162 | CVE-2006-0424 | BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 967 of 17672, showing 5 records out of 88360 total, starting on record 4831, ending on 4835