NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60140 | CVE-2006-1431 | Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60396 | CVE-2006-1691 | SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60652 | CVE-2006-1947 | Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60908 | CVE-2006-2204 | SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array. | 2 | 5.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61164 | CVE-2006-2469 | The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 16521 of 17672, showing 5 records out of 88360 total, starting on record 82601, ending on 82605