NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59388  CVE-2006-0657  Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS.    3.5  Low  2016-12-20  2011-03-07  View
59387  CVE-2006-0656  Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers to access arbitrary files via unspecified vectors, a different vulnerability than CVE-2005-2006.    Medium  2016-12-20  2011-03-07  View
59386  CVE-2006-0655  Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2016-12-20  2008-09-05  View
59385  CVE-2006-0654  check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies.    7.5  High  2016-12-20  2008-09-05  View
59384  CVE-2006-0653  Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter.    7.5  High  2016-12-20  2008-09-05  View

Page 14425 of 17672, showing 5 records out of 88360 total, starting on record 72121, ending on 72125

Actions