NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63387  CVE-2006-4763  IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client"s Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user"s privileges by intercepting the LtpaToken cookie.    7.5  High  2016-12-20  2008-09-05  View
63643  CVE-2006-5037  ** DISPUTED ** MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server"s IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability."    6.8  Medium  2016-12-20  2008-09-05  View
65692  CVE-2006-7149  Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcname parameter to (b) moscomment.php and (c) com_comment.php.    4.3  Medium  2016-12-20  2008-09-05  View
668  CVE-2008-0695  SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action.    7.5  High  2017-01-03  2008-09-05  View
1180  CVE-2008-1220  SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2017-01-03  2008-09-05  View

Page 1042 of 17672, showing 5 records out of 88360 total, starting on record 5206, ending on 5210

Actions