NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62505 | CVE-2006-3837 | delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie"s value, which makes it easier for attackers to steal the cookie and obtain the administrator"s password hash after logout. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63017 | CVE-2006-4378 | ** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in the Rssxt component for Joomla! (com_rssxt), possibly 2.0 Beta 1 or 1.0 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) pinger.php, (2) RPC.php, or (3) rssxt.php. NOTE: another researcher has disputed this issue, saying that the attacker can not control this parameter. In addition, as of 20060825, the original researcher has appeared to be unreliable with some other past reports. CVE has not performed any followup analysis with respect to this issue. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64809 | CVE-2006-6248 | index.php in GPhotos 1.5 allows remote attackers to obtain sensitive information via an invalid rep parameter, which reveals the full path in an error message. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View | |
65321 | CVE-2006-6777 | Cross-site scripting (XSS) vulnerability in index.cfm in Future Internet allows remote attackers to inject arbitrary web script or HTML via the categoryId parameter in a Portal.ShowPage action. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65578 | CVE-2006-7035 | Directory traversal vulnerability in make_thumbnail.php in Super Link Exchange Script 1.0 allows remote attackers to read arbitrary files via ".." sequences in the imgpath parameter. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View |
Page 16256 of 17672, showing 5 records out of 88360 total, starting on record 81276, ending on 81280