NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61784  CVE-2006-3104  users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.    Medium  2016-12-20  2011-03-07  View
62040  CVE-2006-3362  Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.    5.1  Medium  2016-12-20  2011-03-07  View
62296  CVE-2006-3622  The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a " (single quote) in the p parameter, which displays the path in an error message. NOTE: it is not clear whether this is SQL injection or a forced SQL error.    Medium  2016-12-20  2008-09-05  View
62552  CVE-2006-3893  Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML document.    10  High  2016-12-20  2011-03-07  View
62808  CVE-2006-4161  Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter.    Medium  2016-12-20  2008-09-05  View

Page 16678 of 17672, showing 5 records out of 88360 total, starting on record 83386, ending on 83390

Actions