NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60081  CVE-2006-1372  Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.    Medium  2016-12-20  2011-03-07  View
60337  CVE-2006-1630  The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."    Medium  2016-12-20  2011-03-07  View
60593  CVE-2006-1888  phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script. NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages.    6.8  Medium  2016-12-20  2011-08-10  View
60849  CVE-2006-2144  PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.    6.4  Medium  2016-12-20  2011-03-07  View
61361  CVE-2006-2676  Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.    Medium  2016-12-20  2008-09-05  View

Page 14903 of 17672, showing 5 records out of 88360 total, starting on record 74511, ending on 74515

Actions