NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63387 | CVE-2006-4763 | IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client"s Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user"s privileges by intercepting the LtpaToken cookie. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63643 | CVE-2006-5037 | ** DISPUTED ** MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server"s IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability." | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65692 | CVE-2006-7149 | Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcname parameter to (b) moscomment.php and (c) com_comment.php. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
668 | CVE-2008-0695 | SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
1180 | CVE-2008-1220 | SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 1042 of 17672, showing 5 records out of 88360 total, starting on record 5206, ending on 5210