NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59649  CVE-2006-0922  CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.    Medium  2016-12-20  2008-09-05  View
59905  CVE-2006-1191  Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.    Medium  2016-12-20  2011-03-07  View
60161  CVE-2006-1452  Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.    4.6  Medium  2016-12-20  2011-03-07  View
60417  CVE-2006-1712  Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.    2.6  Low  2016-12-20  2011-03-07  View
60673  CVE-2006-1968  Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.    5.8  Medium  2016-12-20  2011-03-07  View

Page 132 of 17672, showing 5 records out of 88360 total, starting on record 656, ending on 660

Actions