NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60213  CVE-2006-1504  Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.    5.1  Medium  2016-12-20  2011-03-07  View
60469  CVE-2006-1764  Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this information is unknown; the details are obtained from third party information.    7.8  High  2016-12-20  2011-03-07  View
60725  CVE-2006-2020  Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.    7.8  High  2016-12-20  2011-03-07  View
60981  CVE-2006-2278  SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the (2) Lsnrow parameter to (c) showcat.php; or the (3) rows parameter to index.php.    Medium  2016-12-20  2011-03-07  View
61237  CVE-2006-2542  xmcdconfig in xmcd for Debian GNU/Linux 2.6-17.1 creates /var/lib/cddb and /var/lib/xmcd/discog with world writable permissions, which allows local users to cause a denial of service (disk consumption).    2.1  Low  2016-12-20  2008-09-05  View

Page 16473 of 17672, showing 5 records out of 88360 total, starting on record 82361, ending on 82365

Actions