NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59888 | CVE-2006-1166 | Monotone 0.25 and earlier, when a user creates a file in a directory called "mt", and when checking out that file on a case-insensitive file system such as Windows or Mac OS X, places the file into the "MT" bookkeeping directory, which could allow context-dependent attackers to execute arbitrary Lua programs as the user running monotone. | 2 | 3.7 | Low | 2016-12-20 | 2011-03-07 | View | |
60144 | CVE-2006-1435 | Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter). | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
60400 | CVE-2006-1695 | The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/fbps-[PID]. | 2 | 1.2 | Low | 2016-12-20 | 2011-03-07 | View | |
60656 | CVE-2006-1951 | Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60912 | CVE-2006-2209 | Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16763 of 17672, showing 5 records out of 88360 total, starting on record 83811, ending on 83815