NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59073  CVE-2006-0334  Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the original researcher notification shows an XSS manipulation in "Keywords".    4.3  Medium  2016-12-20  2011-03-07  View
59841  CVE-2006-1119  fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.    Medium  2016-12-20  2011-07-25  View
60353  CVE-2006-1648  SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker"s machine and read a value that is used as a parameter to malloc.    Medium  2016-12-20  2011-03-07  View
60865  CVE-2006-2160  Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp (Russcom.Loginphp) allows remote attackers to inject arbitrary web script or HTML via the username field when registering.    4.3  Medium  2016-12-20  2008-09-05  View
61121  CVE-2006-2422  phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender"s e-mail address as an "additional contact".    Medium  2016-12-20  2011-03-07  View

Page 15472 of 17672, showing 5 records out of 88360 total, starting on record 77356, ending on 77360

Actions