NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65262  CVE-2006-6718  The Allied Telesis AT-9000/24 Ethernet switch has a default password for its admin account, "manager," which allows remote attackers to perform unauthorized actions.    7.5  High  2016-12-20  2008-09-05  View
65518  CVE-2006-6975  ** DISPUTED ** PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the class_pwd parameter. NOTE: this issue has been disputed by CVE and multiple third parties, who state that $class_pwd is set to a static value before the relevant include statement.    5.1  Medium  2016-12-20  2008-09-05  View
239  CVE-2008-0254  SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.    6.8  Medium  2017-01-03  2008-09-05  View
65775  CVE-2006-7232  sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.    3.5  Low  2016-12-20  2010-08-21  View
495  CVE-2008-0520  Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.    7.5  High  2017-01-03  2011-03-07  View

Page 14443 of 17672, showing 5 records out of 88360 total, starting on record 72211, ending on 72215

Actions