NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64194 | CVE-2006-5599 | Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE: it is likely that this issue overlaps one of the Oracle VulnIDs covered by CVE-2006-5351. Oracle has not publicly disputed claims by a reliable researcher that this has been fixed by the October 2006 CPU. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
64450 | CVE-2006-5875 | eoc.py in Enemies of Carlotta (EoC) before 1.2.4 allows remote attackers to execute arbitrary commands via shell metacharacters in an "SMTP level e-mail address". | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
64706 | CVE-2006-6145 | CRYPTOCard CRYPTO-Server before 6.4.56 stores LDAP credentials in plaintext in UninstallerDatainstallvariables.properties, which has insecure permissions and allows local users to obtain the credentials. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 2.1 | Low | 2016-12-20 | 2011-03-07 | View | |
64962 | CVE-2006-6417 | PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65218 | CVE-2006-6674 | Ozeki HTTP-SMS Gateway 1.0, and possibly earlier, stores usernames and passwords in plaintext in the HKLMSoftwareOzekiSMSServerCurrentVersionPluginshttpsmsgate registry key, which allows local users to obtain sensitive information. | 2 | 2.1 | Low | 2016-12-20 | 2011-08-25 | View |
Page 1142 of 17672, showing 5 records out of 88360 total, starting on record 5706, ending on 5710