NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62505  CVE-2006-3837  delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie"s value, which makes it easier for attackers to steal the cookie and obtain the administrator"s password hash after logout.    Medium  2016-12-20  2008-09-05  View
63017  CVE-2006-4378  ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) pinger.php, (2) RPC.php, or (3) rssxt.php. NOTE: another researcher has disputed this issue, saying that the attacker can not control this parameter. In addition, as of 20060825, the original researcher has appeared to be unreliable with some other past reports. CVE has not performed any followup analysis with respect to this issue.    7.5  High  2016-12-20  2008-09-05  View
64809  CVE-2006-6248  index.php in GPhotos 1.5 allows remote attackers to obtain sensitive information via an invalid rep parameter, which reveals the full path in an error message.    7.8  High  2016-12-20  2008-09-05  View
65321  CVE-2006-6777  Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action.    6.8  Medium  2016-12-20  2008-09-05  View
65578  CVE-2006-7035  Directory traversal vulnerability in make_thumbnail.php in Super Link Exchange Script 1.0 allows remote attackers to read arbitrary files via ".." sequences in the imgpath parameter.    7.8  High  2016-12-20  2008-09-05  View

Page 16256 of 17672, showing 5 records out of 88360 total, starting on record 81276, ending on 81280

Actions