NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59884 | CVE-2006-1162 | Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a .. (dot dot) in the op parameter, as demonstrated by inserting malicious Email parameters into list.gtdat, then accessing list.gtdat using the op parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60140 | CVE-2006-1431 | Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60396 | CVE-2006-1691 | SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60652 | CVE-2006-1947 | Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60908 | CVE-2006-2204 | SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array. | 2 | 5.5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16377 of 17672, showing 5 records out of 88360 total, starting on record 81881, ending on 81885