NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60372 | CVE-2006-1667 | SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s from being set within slides.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60628 | CVE-2006-1923 | Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) RSS/RSS.php and (2) possibly other vectors. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
60884 | CVE-2006-2179 | Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61140 | CVE-2006-2441 | Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create a new game. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61396 | CVE-2006-2711 | Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1246 of 17672, showing 5 records out of 88360 total, starting on record 6226, ending on 6230