NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59971  CVE-2006-1257  The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.    7.5  High  2016-12-20  2008-09-05  View
60739  CVE-2006-2034  SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php.    7.5  High  2016-12-20  2008-09-05  View
65604  CVE-2006-7061  Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks.    9.3  High  2016-12-20  2008-09-05  View
580  CVE-2008-0605  Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.    4.3  Medium  2017-01-03  2008-09-05  View
1092  CVE-2008-1131  Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.    3.5  Low  2017-01-03  2008-09-05  View

Page 16405 of 17672, showing 5 records out of 88360 total, starting on record 82021, ending on 82025

Actions