NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60146 | CVE-2006-1437 | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61170 | CVE-2006-2475 | Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View | |
61426 | CVE-2006-2741 | Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
62962 | CVE-2006-4323 | SQL injection vulnerability in list.php in CityForFree indexcity 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64242 | CVE-2006-5648 | Ubuntu Linux 6.10 for the PowerPC (PPC) allows local users to cause a denial of service (resource consumption) by using the (1) sys_get_robust_list and (2) sys_set_robust_list functions to create processes that cannot be killed. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 1586 of 17672, showing 5 records out of 88360 total, starting on record 7926, ending on 7930