NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59643  CVE-2006-0916  Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user"s browser to send the form data to another domain.    7.5  High  2016-12-20  2011-03-07  View
60411  CVE-2006-1706  Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries.    7.5  High  2016-12-20  2011-03-07  View
60667  CVE-2006-1962  SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.    7.5  High  2016-12-20  2011-08-05  View
63227  CVE-2006-4594  Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1) confirm.php or (2) login.php. NOTE: the include_location parameter to index.php is already covered by CVE-2005-1681.    7.5  High  2016-12-20  2011-03-07  View
63483  CVE-2006-4867  SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."    7.5  High  2016-12-20  2011-03-07  View

Page 15690 of 17672, showing 5 records out of 88360 total, starting on record 78446, ending on 78450

Actions