NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62652 | CVE-2006-3994 | SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 62908 | CVE-2006-4269 | ** DISPUTED ** PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by third party researchers, stating that there is no mosConfig_absolute_path parameter and no admin.x-shop.php file in the reported package. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 63164 | CVE-2006-4531 | PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. | 2 | 7.5 | High | 2016-12-20 | 2012-12-12 | View | |
| 65981 | CVE-2005-0217 | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 66493 | CVE-2005-0743 | The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 14931 of 17672, showing 5 records out of 88360 total, starting on record 74651, ending on 74655