NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62042 | CVE-2006-3364 | SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62298 | CVE-2006-3624 | Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
62554 | CVE-2006-3896 | The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX. | 2 | 4.9 | Medium | 2016-12-20 | 2011-03-07 | View | |
62810 | CVE-2006-4163 | ** DISPUTED ** PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NOTE: another researcher was unable to find a way to execute code after including it via a URL. CVE analysis as of 20060816 was inconclusive. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63066 | CVE-2006-4431 | Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a (1) empty or (2) crafted PHP session identifier (PHPSESSID). | 2 | 7.5 | High | 2016-12-20 | 2016-10-17 | View |
Page 16690 of 17672, showing 5 records out of 88360 total, starting on record 83446, ending on 83450