NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61952 | CVE-2006-3273 | Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 rc1 allows remote attackers to inject arbitrary web script or HTML via the user parameter ("New Name" field). | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
62464 | CVE-2006-3796 | DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63744 | CVE-2006-5138 | Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64256 | CVE-2006-5662 | SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page." | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64768 | CVE-2006-6207 | ** DISPUTED ** SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 16012 of 17672, showing 5 records out of 88360 total, starting on record 80056, ending on 80060