NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59643 | CVE-2006-0916 | Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user"s browser to send the form data to another domain. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60411 | CVE-2006-1706 | Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60667 | CVE-2006-1962 | SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php. | 2 | 7.5 | High | 2016-12-20 | 2011-08-05 | View | |
63227 | CVE-2006-4594 | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1) confirm.php or (2) login.php. NOTE: the include_location parameter to index.php is already covered by CVE-2005-1681. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
63483 | CVE-2006-4867 | SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum." | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 15690 of 17672, showing 5 records out of 88360 total, starting on record 78446, ending on 78450