NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59178  CVE-2006-0440  Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.    Medium  2016-12-20  2008-09-05  View
59177  CVE-2006-0439  Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt.    Medium  2016-12-20  2011-03-07  View
59176  CVE-2006-0438  Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.    Medium  2016-12-20  2011-03-07  View
59175  CVE-2006-0437  Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.    4.3  Medium  2016-12-20  2011-03-07  View
59174  CVE-2006-0436  Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.    7.2  High  2016-12-20  2011-03-07  View

Page 14467 of 17672, showing 5 records out of 88360 total, starting on record 72331, ending on 72335

Actions