NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62421 | CVE-2006-3753 | setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
62677 | CVE-2006-4019 | Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users. | 2 | 6.4 | Medium | 2016-12-20 | 2016-10-17 | View | |
62933 | CVE-2006-4294 | Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
64213 | CVE-2006-5618 | Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the ad_direct parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
64469 | CVE-2006-5894 | Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16178 of 17672, showing 5 records out of 88360 total, starting on record 80886, ending on 80890