NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59649 | CVE-2006-0922 | CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
59905 | CVE-2006-1191 | Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
60161 | CVE-2006-1452 | Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
60417 | CVE-2006-1712 | Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
60673 | CVE-2006-1968 | Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 132 of 17672, showing 5 records out of 88360 total, starting on record 656, ending on 660