NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60955  CVE-2006-2252  Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.    6.4  Medium  2016-12-20  2011-03-07  View
61211  CVE-2006-2516  mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption["nocommon"] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2) xoopsConfig[theme_set] to index.php, as demonstrated by injecting PHP sequences into a log file.    5.1  Medium  2016-12-20  2011-10-03  View
61467  CVE-2006-2782  Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.    4.3  Medium  2016-12-20  2011-03-07  View
61723  CVE-2006-3039  Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed."    2.6  Low  2016-12-20  2011-03-07  View
61979  CVE-2006-3300  PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.    7.5  High  2016-12-20  2011-03-07  View

Page 16324 of 17672, showing 5 records out of 88360 total, starting on record 81616, ending on 81620

Actions