NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59577  CVE-2006-0847  Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.    Medium  2016-12-20  2011-03-07  View
59833  CVE-2006-1111  Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.    7.5  High  2016-12-20  2008-09-10  View
60089  CVE-2006-1380  ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.    7.2  High  2016-12-20  2013-01-24  View
60345  CVE-2006-1640  Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14 allows remote attackers to inject arbitrary web script or HTML via the email parameter.    2.6  Low  2016-12-20  2011-03-07  View
60601  CVE-2006-1896  Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.    Medium  2016-12-20  2008-09-05  View

Page 1085 of 17672, showing 5 records out of 88360 total, starting on record 5421, ending on 5425

Actions