NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62917 | CVE-2006-4278 | PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the mainnav parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
63173 | CVE-2006-4540 | Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
63429 | CVE-2006-4808 | Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
63685 | CVE-2006-5079 | PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
63941 | CVE-2006-5340 | Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related to bypassing input validation for SQL injection related to convert_to_lrs_layer and dbms_assert, and DB17 is related to SQL injection in the trigger in the SDO_DROP_USER package. | 2 | 7.1 | High | 2016-12-20 | 2016-04-29 | View |
Page 1159 of 17672, showing 5 records out of 88360 total, starting on record 5791, ending on 5795