NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60144 | CVE-2006-1435 | Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter). | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
62448 | CVE-2006-3780 | Keyifweb Keyif Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) ANKET/anket.mdb, (2) HABER/keyifweb.mdb, (3) ASP/download.mdb, or (4) SAYAC/aktif.mdb in the database/A9S7G6ASD790 directory. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64496 | CVE-2006-5921 | Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields. NOTE: this issue may overlap CVE-2006-5195. | 2 | 5.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65008 | CVE-2006-6463 | Unrestricted file upload vulnerability in admin/add.php in Midicart allows remote authenticated users to upload arbitrary .php files, and possibly other files, to the images/ directory under the web root. | 2 | 6.5 | Medium | 2016-12-20 | 2008-09-05 | View | |
241 | CVE-2008-0256 | Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 1575 of 17672, showing 5 records out of 88360 total, starting on record 7871, ending on 7875