NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 61886 | CVE-2006-3207 | Directory traversal vulnerability in newpost.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the id parameter, as demonstrated by injecting a Perl CGI script using "[NR]" sequences in the message parameter, then calling close.php with modified id and t_id parameters to chmod the script. NOTE: this issue might be resultant from dynamic variable evaluation. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 62654 | CVE-2006-3996 | SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 63678 | CVE-2006-5072 | The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack. | 2 | 6.2 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 64190 | CVE-2006-5595 | Unspecified vulnerability in the AirPcap support in Wireshark (formerly Ethereal) 0.99.3 has unspecified attack vectors related to WEP key parsing. | 2 | 5 | Medium | 2016-12-20 | 2012-08-13 | View | |
| 64446 | CVE-2006-5871 | smbfs in Linux kernel 2.6.8 and other versions, and 2.4.x before 2.4.34, when UNIX extensions are enabled, ignores certain mount options, which could cause clients to use server-specified uid, gid and mode settings. | 2 | 4.1 | Medium | 2016-12-20 | 2010-08-21 | View |
Page 15367 of 17672, showing 5 records out of 88360 total, starting on record 76831, ending on 76835