NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59948 | CVE-2006-1234 | SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60972 | CVE-2006-2269 | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
61228 | CVE-2006-2533 | Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2) leaveComments.php in Destiney Rated Images Script 0.5.0 does not properly filter all vulnerable HTML tags, which allows remote attackers to inject arbitrary web script or HTML via Javascript in a DIV tag. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61484 | CVE-2006-2799 | Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61996 | CVE-2006-3318 | SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters. | 2 | 5.1 | Medium | 2016-12-20 | 2011-08-05 | View |
Page 1620 of 17672, showing 5 records out of 88360 total, starting on record 8096, ending on 8100