NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63970  CVE-2006-5369  Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02.    10  High  2016-12-20  2012-10-22  View
64226  CVE-2006-5631  Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via arbitrary query strings when the action parameter is not "1", as demonstrated using script in the action parameter, a different vulnerability than CVE-2006-5632.    6.8  Medium  2016-12-20  2008-09-05  View
64482  CVE-2006-5907  SQL injection vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary SQL commands via the id parameter.    7.5  High  2016-12-20  2008-09-05  View
64738  CVE-2006-6177  SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and " (apostrophe) (%2500%2527).    7.5  High  2016-12-20  2011-03-07  View
64994  CVE-2006-6449  Vt-Forum Lite 1.3 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.    6.4  Medium  2016-12-20  2011-03-07  View

Page 1332 of 17672, showing 5 records out of 88360 total, starting on record 6656, ending on 6660

Actions