NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
57114  CVE-2007-5026  dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb.    Medium  2017-01-07  2008-11-15  View
57370  CVE-2007-5294  PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter.    6.8  Medium  2017-01-07  2011-03-07  View
57882  CVE-2007-5831  Directory traversal vulnerability in fileSystem.do in SSL-Explorer before 0.2.14 allows remote attackers to access arbitrary files via directory traversal sequences in the path parameter. NOTE: some of these details are obtained from third party information.    Medium  2017-01-07  2012-10-30  View
58394  CVE-2007-6399  index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action.    6.5  Medium  2017-01-07  2008-11-15  View
59162  CVE-2006-0424  BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information.    Medium  2016-12-20  2011-03-07  View

Page 967 of 17672, showing 5 records out of 88360 total, starting on record 4831, ending on 4835

Actions