NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
64750  CVE-2006-6189  SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter.    7.5  High  2016-12-20  2008-09-05  View
65006  CVE-2006-6461  tr1.php in Yourfreeworld Stylish Text Ads Script allows remote attackers to obtain the installation path via an invalid id parameter, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2508.    7.8  High  2016-12-20  2008-09-05  View
65262  CVE-2006-6718  The Allied Telesis AT-9000/24 Ethernet switch has a default password for its admin account, "manager," which allows remote attackers to perform unauthorized actions.    7.5  High  2016-12-20  2008-09-05  View
65518  CVE-2006-6975  ** DISPUTED ** PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the class_pwd parameter. NOTE: this issue has been disputed by CVE and multiple third parties, who state that $class_pwd is set to a static value before the relevant include statement.    5.1  Medium  2016-12-20  2008-09-05  View
239  CVE-2008-0254  SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.    6.8  Medium  2017-01-03  2008-09-05  View

Page 16646 of 17672, showing 5 records out of 88360 total, starting on record 83226, ending on 83230

Actions