NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62205 | CVE-2006-3531 | includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62461 | CVE-2006-3793 | PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SD_DIR parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
62717 | CVE-2006-4060 | PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62973 | CVE-2006-4334 | Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference. | 2 | 5 | Medium | 2016-12-20 | 2013-09-05 | View | |
63229 | CVE-2006-4596 | PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) hauptverzeichniss parameter in includes/login_check.php and the (2) template_back parameter in admin/login/content/user_daten.php. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1488 of 17672, showing 5 records out of 88360 total, starting on record 7436, ending on 7440