NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62745  CVE-2006-4088  Multiple cross-site scripting (XSS) vulnerabilities in CivicSpace 0.8.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject, (2) Comment, and (3) Add new comment sections.    4.3  Medium  2016-12-20  2008-09-05  View
64281  CVE-2006-5706  Unspecified vulnerabilities in PHP, probably before 5.2.0, allow local users to bypass open_basedir restrictions and perform unspecified actions via unspecified vectors involving the (1) chdir and (2) tempnam functions. NOTE: the tempnam vector might overlap CVE-2006-1494.    7.2  High  2016-12-20  2008-09-05  View
64793  CVE-2006-6232  PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.    7.5  High  2016-12-20  2008-09-05  View
282  CVE-2008-0297  PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.    Medium  2017-01-03  2008-09-05  View
538  CVE-2008-0563  Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.    4.3  Medium  2017-01-03  2008-09-05  View

Page 16165 of 17672, showing 5 records out of 88360 total, starting on record 80821, ending on 80825

Actions