NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59971 | CVE-2006-1257 | The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60739 | CVE-2006-2034 | SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65604 | CVE-2006-7061 | Scriptsez.net E-Dating System stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read private messages and leverage them for cross-site scripting (XSS) attacks. | 2 | 9.3 | High | 2016-12-20 | 2008-09-05 | View | |
580 | CVE-2008-0605 | Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
1092 | CVE-2008-1131 | Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms. | 2 | 3.5 | Low | 2017-01-03 | 2008-09-05 | View |
Page 16405 of 17672, showing 5 records out of 88360 total, starting on record 82021, ending on 82025