NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72985 | CVE-2004-2608 | SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator"s account. | 2 | 5 | Medium | 2016-12-20 | 2010-05-29 | View | |
58905 | CVE-2006-0165 | Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
59161 | CVE-2006-0423 | BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59417 | CVE-2006-0686 | add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
59673 | CVE-2006-0946 | Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16311 of 17672, showing 5 records out of 88360 total, starting on record 81551, ending on 81555