NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 63909 | CVE-2006-5306 | Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 64165 | CVE-2006-5564 | Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 64421 | CVE-2006-5846 | Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773. | 2 | 6.4 | Medium | 2016-12-20 | 2016-11-18 | View | |
| 166 | CVE-2008-0180 | Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 65702 | CVE-2006-7159 | Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 14490 of 17672, showing 5 records out of 88360 total, starting on record 72446, ending on 72450