NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60955 | CVE-2006-2252 | Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61211 | CVE-2006-2516 | mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption["nocommon"] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2) xoopsConfig[theme_set] to index.php, as demonstrated by injecting PHP sequences into a log file. | 2 | 5.1 | Medium | 2016-12-20 | 2011-10-03 | View | |
61467 | CVE-2006-2782 | Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
61723 | CVE-2006-3039 | Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed." | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
61979 | CVE-2006-3300 | PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 16324 of 17672, showing 5 records out of 88360 total, starting on record 81616, ending on 81620