NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59058 | CVE-2006-0318 | SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action. | 2 | 7.5 | High | 2016-12-20 | 2011-08-08 | View | |
| 59057 | CVE-2006-0317 | Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59056 | CVE-2006-0316 | Buffer overflow in YGPPicFinder.DLL in AOL You"ve Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
| 59055 | CVE-2006-0315 | index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure. | 2 | 5.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 59054 | CVE-2006-0314 | PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users" passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 14491 of 17672, showing 5 records out of 88360 total, starting on record 72451, ending on 72455