NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65365 | CVE-2006-6822 | myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account"s username in a modified MM_recordId parameter. | 2 | 3.5 | Low | 2016-12-20 | 2011-03-07 | View | |
65622 | CVE-2006-7079 | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption["pagetype"] variable. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
73046 | CVE-2004-2669 | Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters including (1) s, w, and d in users.php, (2) id in comments.php, (3) rusername in auth.php, or (4) h in plug.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
58966 | CVE-2006-0226 | Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
59222 | CVE-2006-0484 | Directory traversal vulnerability in Vis.pl, as part of the FACE CONTROL product, allows remote attackers to read arbitrary files via a .. (dot dot) in any parameter that opens a file, such as (1) s or (2) p. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 16664 of 17672, showing 5 records out of 88360 total, starting on record 83316, ending on 83320