NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 64155 | CVE-2006-5554 | Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter in albumview.php to upload a text/plain .gif file containing PHP code, which is executed by index.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 64667 | CVE-2006-6106 | Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.18.6, and 2.6.19.x, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via CAPI messages with a large value for the length of the (1) manu (manufacturer) or (2) serial (serial number) field. | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View | |
| 64923 | CVE-2006-6377 | Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 65179 | CVE-2006-6635 | PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the jcms_root_path parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 668 | CVE-2008-0695 | SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 14572 of 17672, showing 5 records out of 88360 total, starting on record 72856, ending on 72860