NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 61380 | CVE-2006-2695 | admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory. | 2 | 5.1 | Medium | 2016-12-20 | 2013-09-10 | View | |
| 61636 | CVE-2006-2952 | Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) Default_Theme parameter to header.php or (2) ModPath parameter to modules/cluster-paradise/cluster-E.php. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 62660 | CVE-2006-4002 | Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 65733 | CVE-2006-7190 | Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 453 | CVE-2008-0475 | ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 15579 of 17672, showing 5 records out of 88360 total, starting on record 77891, ending on 77895