NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61784 | CVE-2006-3104 | users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
62040 | CVE-2006-3362 | Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
62296 | CVE-2006-3622 | The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a " (single quote) in the p parameter, which displays the path in an error message. NOTE: it is not clear whether this is SQL injection or a forced SQL error. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
62552 | CVE-2006-3893 | Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML document. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
62808 | CVE-2006-4161 | Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 16678 of 17672, showing 5 records out of 88360 total, starting on record 83386, ending on 83390