NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60374  CVE-2006-1669  SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitrary SQL commands via the T parameter. NOTE: this issue can be leveraged to execute arbitrary shell commands since the username is later processed in an eval() call, but since the username originated from the SQL injection, it could be a resultant issue.    6.4  Medium  2016-12-20  2008-09-05  View
60630  CVE-2006-1925  Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.    4.3  Medium  2016-12-20  2008-09-05  View
61142  CVE-2006-2443  The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.    4.6  Medium  2016-12-20  2008-09-05  View
62934  CVE-2006-4295  Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter.    4.3  Medium  2016-12-20  2008-09-05  View
63190  CVE-2006-4557  ** DISPUTED ** PHP remote file inclusion vulnerability in plugins/plugins.php in Bob Jewell Discloser 0.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the type parameter. NOTE: another researcher has stated that an attacker cannot control the type parameter. As of 20060901, CVE analysis concurs with the dispute.    7.5  High  2016-12-20  2008-09-05  View

Page 1418 of 17672, showing 5 records out of 88360 total, starting on record 7086, ending on 7090

Actions