NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63909  CVE-2006-5306  Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php.    6.8  Medium  2016-12-20  2011-03-07  View
64165  CVE-2006-5564  Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.    4.3  Medium  2016-12-20  2011-03-07  View
64421  CVE-2006-5846  Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.    6.4  Medium  2016-12-20  2016-11-18  View
166  CVE-2008-0180  Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.    4.3  Medium  2017-01-03  2008-09-05  View
65702  CVE-2006-7159  Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action.    6.4  Medium  2016-12-20  2008-09-05  View

Page 14490 of 17672, showing 5 records out of 88360 total, starting on record 72446, ending on 72450

Actions