NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58395 | CVE-2007-6400 | Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
59163 | CVE-2006-0425 | BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60443 | CVE-2006-1738 | Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60955 | CVE-2006-2252 | Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61211 | CVE-2006-2516 | mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption["nocommon"] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2) xoopsConfig[theme_set] to index.php, as demonstrated by injecting PHP sequences into a log file. | 2 | 5.1 | Medium | 2016-12-20 | 2011-10-03 | View |
Page 1007 of 17672, showing 5 records out of 88360 total, starting on record 5031, ending on 5035