NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59162 | CVE-2006-0424 | BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View | |
59418 | CVE-2006-0687 | process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
59674 | CVE-2006-0947 | Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59930 | CVE-2006-1216 | Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
60186 | CVE-2006-1477 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 16317 of 17672, showing 5 records out of 88360 total, starting on record 81581, ending on 81585