NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64710 | CVE-2006-6149 | SQL injection vulnerability in index.asp in JiRos FAQ Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the tID parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64966 | CVE-2006-6421 | Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user. | 2 | 6 | Medium | 2016-12-20 | 2008-09-05 | View | |
65222 | CVE-2006-6678 | The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65478 | CVE-2006-6935 | SQL injection vulnerability in the login component in Portix-PHP 0.4.2 allows remote attackers to execute arbitrary SQL commands via the username and passwd (password) fields. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65735 | CVE-2006-7192 | Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag. | 2 | 4.3 | Medium | 2016-12-20 | 2008-11-13 | View |
Page 1166 of 17672, showing 5 records out of 88360 total, starting on record 5826, ending on 5830