NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60387  CVE-2006-1682  Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script.    4.3  Medium  2016-12-20  2011-03-07  View
60643  CVE-2006-1938  Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.    Medium  2016-12-20  2011-03-07  View
60899  CVE-2006-2195  Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.    6.8  Medium  2016-12-20  2011-03-07  View
61155  CVE-2006-2460  Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.    6.4  Medium  2016-12-20  2011-03-07  View
61923  CVE-2006-3244  Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order parameter in buglist.php and the (2) bug parameter in query.php.    5.1  Medium  2016-12-20  2011-03-07  View

Page 16682 of 17672, showing 5 records out of 88360 total, starting on record 83406, ending on 83410

Actions