NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63382 | CVE-2006-4758 | phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View | |
64150 | CVE-2006-5549 | ** DISPUTED ** PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party researcher who states that AMFPHP_BASE is a constant. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64406 | CVE-2006-5831 | PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the load_page parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64918 | CVE-2006-6372 | Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php in JAB Guest Book 20061205 allow remote attackers to inject arbitrary web script or HTML via the (1) topic or (2) message parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65174 | CVE-2006-6630 | PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 1012 of 17672, showing 5 records out of 88360 total, starting on record 5056, ending on 5060