NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60253  CVE-2006-1545  Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.    High  2016-12-20  2011-03-07  View
60509  CVE-2006-1804  SQL injection vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to execute arbitrary SQL commands via the sql_query parameter.    7.5  High  2016-12-20  2011-03-07  View
60765  CVE-2006-2060  Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to erase the initial static portion of a filename.    6.4  Medium  2016-12-20  2011-03-07  View
61021  CVE-2006-2319  Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.    Medium  2016-12-20  2011-03-07  View
61277  CVE-2006-2582  The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors.    7.5  High  2016-12-20  2011-03-07  View

Page 16706 of 17672, showing 5 records out of 88360 total, starting on record 83526, ending on 83530

Actions