NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59073 | CVE-2006-0334 | Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the original researcher notification shows an XSS manipulation in "Keywords". | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59841 | CVE-2006-1119 | fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message. | 2 | 4 | Medium | 2016-12-20 | 2011-07-25 | View | |
| 60353 | CVE-2006-1648 | SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker"s machine and read a value that is used as a parameter to malloc. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 60865 | CVE-2006-2160 | Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp (Russcom.Loginphp) allows remote attackers to inject arbitrary web script or HTML via the username field when registering. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 61121 | CVE-2006-2422 | phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender"s e-mail address as an "additional contact". | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 15472 of 17672, showing 5 records out of 88360 total, starting on record 77356, ending on 77360