NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60056  CVE-2006-1347  SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.    7.5  High  2016-12-20  2011-03-07  View
60312  CVE-2006-1605  Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknown vectors involving "parsed PHP."    7.5  High  2016-12-20  2011-03-07  View
61592  CVE-2006-2908  The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.    7.5  High  2016-12-20  2011-03-07  View
62360  CVE-2006-3692  ** DISPUTED ** PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating that the $lm_path variable is set to a constant value. As of 20060726, CVE concurs with the vendor based on SecurityTracker"s post-disclosure analysis.    7.5  High  2016-12-20  2008-09-05  View
64152  CVE-2006-5551  Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command.    7.5  High  2016-12-20  2011-03-07  View

Page 14540 of 17672, showing 5 records out of 88360 total, starting on record 72696, ending on 72700

Actions