NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63970 | CVE-2006-5369 | Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02. | 2 | 10 | High | 2016-12-20 | 2012-10-22 | View | |
64226 | CVE-2006-5631 | Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via arbitrary query strings when the action parameter is not "1", as demonstrated using script in the action parameter, a different vulnerability than CVE-2006-5632. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
64482 | CVE-2006-5907 | SQL injection vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64738 | CVE-2006-6177 | SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and " (apostrophe) (%2500%2527). | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64994 | CVE-2006-6449 | Vt-Forum Lite 1.3 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1332 of 17672, showing 5 records out of 88360 total, starting on record 6656, ending on 6660