NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60593 | CVE-2006-1888 | phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script. NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages. | 2 | 6.8 | Medium | 2016-12-20 | 2011-08-10 | View | |
60849 | CVE-2006-2144 | PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61105 | CVE-2006-2406 | Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
61361 | CVE-2006-2676 | Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61617 | CVE-2006-2933 | kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop. | 2 | 4.6 | Medium | 2016-12-20 | 2010-08-21 | View |
Page 1038 of 17672, showing 5 records out of 88360 total, starting on record 5186, ending on 5190