NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60617  CVE-2006-1912  MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.    5.8  Medium  2016-12-20  2011-03-07  View
60873  CVE-2006-2168  FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1.    7.5  High  2016-12-20  2008-09-05  View
61129  CVE-2006-2430  IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.    10  High  2016-12-20  2011-03-07  View
61385  CVE-2006-2700  SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter.    5.1  Medium  2016-12-20  2011-03-07  View
61641  CVE-2006-2957  Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.    4.3  Medium  2016-12-20  2008-09-05  View

Page 1180 of 17672, showing 5 records out of 88360 total, starting on record 5896, ending on 5900

Actions