NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60459 | CVE-2006-1754 | SQL injection vulnerability in index.php in SWSoft Confixx 3.0.6, 3.0.8, and 3.1.2 allows remote attackers to execute arbitrary SQL commands via the SID parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60715 | CVE-2006-2010 | Multiple SQL injection vulnerabilities in check_login.asp in Bloggage allow remote attackers to execute arbitrary SQL commands via the (1) acc_name and (2) password parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60971 | CVE-2006-2268 | SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows remote attackers to bypass authentication and execute arbitrary SQL commands via the admin and ordinary user interface, probably involving the (1) checkuser and (2) checkpass parameters to (a) admin/index.php, and (3) username and (4) password parameters to (b) index.php. NOTE: it was later reported that 0.0.6 is also affected. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61227 | CVE-2006-2532 | stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter, which displays the path in an error message. NOTE: this issue was originally claimed to be SQL injection, but CVE analysis shows that the problem is related to an invalid value that prevents some variables from being set. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
61483 | CVE-2006-2798 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 16415 of 17672, showing 5 records out of 88360 total, starting on record 82071, ending on 82075