NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 60361 | CVE-2006-1656 | vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root. | 2 | 7.2 | High | 2016-12-20 | 2008-09-05 | View | |
| 60617 | CVE-2006-1912 | MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 60873 | CVE-2006-2168 | FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 61129 | CVE-2006-2430 | IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
| 61385 | CVE-2006-2700 | SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 14399 of 17672, showing 5 records out of 88360 total, starting on record 71991, ending on 71995