NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65010 | CVE-2006-6465 | ** DISPUTED ** Directory traversal vulnerability in WBmap.php in WikyBlog 1.3.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter. NOTE: CVE disputes this vulnerability because l is validated by ctype_alpha before use. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
65266 | CVE-2006-6722 | Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65522 | CVE-2006-6979 | The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters. | 2 | 7.5 | High | 2016-12-20 | 2011-06-16 | View | |
243 | CVE-2008-0258 | Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
65779 | CVE-2006-7236 | The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences. | 2 | 9.3 | High | 2016-12-20 | 2009-02-26 | View |
Page 16889 of 17672, showing 5 records out of 88360 total, starting on record 84441, ending on 84445