NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63460 | CVE-2006-4844 | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
63716 | CVE-2006-5110 | Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different vector than CVE-2006-5074. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
63972 | CVE-2006-5371 | Unspecified vulnerability in Oracle Email Center component in Oracle E-Business Suite 11.5.9 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS07. | 2 | 9 | High | 2016-12-20 | 2012-10-22 | View | |
64228 | CVE-2006-5633 | Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64484 | CVE-2006-5909 | generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts. | 2 | 5 | Medium | 2016-12-20 | 2011-10-18 | View |
Page 16037 of 17672, showing 5 records out of 88360 total, starting on record 80181, ending on 80185