NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64829 | CVE-2006-6268 | SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL commands via a url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by a double-encoded NULL and " (apostrophe) (%2500%2527). | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
65598 | CVE-2006-7055 | PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execute arbitrary code via a URL in the inc_dir parameter, a different vector than CVE-2006-1922. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65854 | CVE-2005-0074 | Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code. | 2 | 7.2 | High | 2017-01-03 | 2008-09-05 | View | |
1086 | CVE-2008-1125 | Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) theme_path parameter to core/themes.php and the (2) filename parameter to download.php. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
2366 | CVE-2008-2452 | Cross-site scripting (XSS) vulnerability in the Questionaire (aka pbsurvey) extension 1.2.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 16370 of 17672, showing 5 records out of 88360 total, starting on record 81846, ending on 81850