NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60625 | CVE-2006-1920 | SQL injection vulnerability in index.php in PMTool 1.2.2 allows remote attackers to execute arbitrary SQL commands via the order parameter in the include files (1) user.inc.php, (2) customer.inc.php, and (3) project.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
60881 | CVE-2006-2176 | Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61137 | CVE-2006-2438 | Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter. NOTE: this issue can produce resultant path disclosure when the parameter is invalid. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61393 | CVE-2006-2708 | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read). | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61649 | CVE-2006-2965 | Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box." | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16034 of 17672, showing 5 records out of 88360 total, starting on record 80166, ending on 80170