NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59600 | CVE-2006-0871 | Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
59856 | CVE-2006-1134 | SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60880 | CVE-2006-2175 | PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61136 | CVE-2006-2437 | The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61392 | CVE-2006-2707 | Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 15995 of 17672, showing 5 records out of 88360 total, starting on record 79971, ending on 79975