NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61952  CVE-2006-3273  Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 rc1 allows remote attackers to inject arbitrary web script or HTML via the user parameter ("New Name" field).    2.6  Low  2016-12-20  2008-09-05  View
62464  CVE-2006-3796  DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.    7.5  High  2016-12-20  2008-09-05  View
63744  CVE-2006-5138  Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message.    Medium  2016-12-20  2008-09-05  View
64256  CVE-2006-5662  SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."    7.5  High  2016-12-20  2008-09-05  View
64768  CVE-2006-6207  ** DISPUTED ** SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error.    7.5  High  2016-12-20  2008-09-05  View

Page 16012 of 17672, showing 5 records out of 88360 total, starting on record 80056, ending on 80060

Actions