NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60908 | CVE-2006-2204 | SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array. | 2 | 5.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61164 | CVE-2006-2469 | The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61420 | CVE-2006-2735 | PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
61676 | CVE-2006-2992 | Cross-site scripting (XSS) vulnerability in display.asp in My Photo Scrapbook 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the key_m parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
61932 | CVE-2006-3253 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer." | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View |
Page 16027 of 17672, showing 5 records out of 88360 total, starting on record 80131, ending on 80135