NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59923 | CVE-2006-1209 | PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
60947 | CVE-2006-2244 | Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
62227 | CVE-2006-3553 | PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
62739 | CVE-2006-4082 | Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which allows local users to gain privileges. | 2 | 7.2 | High | 2016-12-20 | 2008-09-05 | View | |
63251 | CVE-2006-4618 | PHP remote file inclusion vulnerability in adodb-postgres7.inc.php in John Lim ADOdb, possibly 4.01 and earlier, as used in Intechnic In-link 2.3.4, allows remote attackers to execute arbitrary PHP code via a URL in the ADODB_DIR parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 149 of 17672, showing 5 records out of 88360 total, starting on record 741, ending on 745