NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60617 | CVE-2006-1912 | MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61385 | CVE-2006-2700 | SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the loginname parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
61641 | CVE-2006-2957 | Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the banurl parameter to add.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
62153 | CVE-2006-3479 | Cross-site request forgery (CSRF) vulnerability in the del_block function in modules/Admin/block.php in Nuked-Klan 1.7.5 and earlier and 1.7 SP4.2 allows remote attackers to delete arbitrary "blocks" via a link with a modified bid parameter in a del_block op on the block page in index.php. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
62409 | CVE-2006-3741 | The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descriptor consumption). | 2 | 4.9 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 15750 of 17672, showing 5 records out of 88360 total, starting on record 78746, ending on 78750