NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58897  CVE-2006-0157  settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.    Medium  2016-12-20  2008-09-05  View
59153  CVE-2006-0415  Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.    4.3  Medium  2016-12-20  2008-09-05  View
59921  CVE-2006-1207  PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.    Medium  2016-12-20  2008-09-05  View
62225  CVE-2006-3551  NCP Secure Enterprise Client (aka VPN/PKI client) 8.30 Build 59, and possibly earlier versions, when the Link Firewall and Personal Firewall are both configured to block all inbound and outbound network traffic, allows context-dependent attackers to send inbound UDP traffic with source port 67 and destination port 68, and outbound UDP traffic with source port 68 and destination port 67.    1.2  Low  2016-12-20  2008-09-05  View
62737  CVE-2006-4080  DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.    2.6  Low  2016-12-20  2008-09-05  View

Page 137 of 17672, showing 5 records out of 88360 total, starting on record 681, ending on 685

Actions