NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60253 | CVE-2006-1545 | Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php. | 2 | 9 | High | 2016-12-20 | 2011-03-07 | View | |
60509 | CVE-2006-1804 | SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60765 | CVE-2006-2060 | Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to erase the initial static portion of a filename. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61021 | CVE-2006-2319 | Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61277 | CVE-2006-2582 | The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 16706 of 17672, showing 5 records out of 88360 total, starting on record 83526, ending on 83530