NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63180  CVE-2006-4547  Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a " (single quote) character in the name, which reveals the details of the underlying SQL query, possibly because of a forced SQL error or SQL injection.    6.5  Medium  2016-12-20  2008-09-05  View
63692  CVE-2006-5086  Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.    6.4  Medium  2016-12-20  2008-09-05  View
64204  CVE-2006-5609  Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "../" sequences in the dir parameter.    Medium  2016-12-20  2008-09-05  View
65228  CVE-2006-6684  Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd before 2.4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long X-Forwarded-For HTTP header. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2016-12-20  2008-09-05  View
717  CVE-2008-0746  SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.    7.5  High  2017-01-03  2008-09-05  View

Page 1360 of 17672, showing 5 records out of 88360 total, starting on record 6796, ending on 6800

Actions