NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62851 | CVE-2006-4210 | nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
| 63363 | CVE-2006-4739 | Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
| 10884 | CVE-2011-4457 | OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element. | 2 | 2.6 | Low | 2017-01-07 | 2011-11-18 | View | |
| 44420 | CVE-2012-2703 | Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to the "$conf variable in settings.php." | 2 | 2.6 | Low | 2017-01-19 | 2012-08-28 | View | |
| 60548 | CVE-2006-1843 | Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View |
Page 15326 of 17672, showing 5 records out of 88360 total, starting on record 76626, ending on 76630