NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60899 | CVE-2006-2195 | Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61155 | CVE-2006-2460 | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61411 | CVE-2006-2726 | PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files via the config[fsBase] parameter in (1) drucken.php, (2) drucken2.php, (3) email_an_benutzer.php, (4) rechnung.php, (5) suche/search.php and (6) adminbereich/admin.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61667 | CVE-2006-2983 | PHP remote file inclusion vulnerability in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in cal.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61923 | CVE-2006-3244 | Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 15975 of 17672, showing 5 records out of 88360 total, starting on record 79871, ending on 79875