NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61309 | CVE-2006-2614 | Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (1) /cr/hd_jobs_db.sh, (2) /cr/hd_plan_checkin.sh, and (3) /cr/oracle_plan_checkin.sh, which allows local users to obtain System Manager passwords. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
61565 | CVE-2006-2880 | Cross-site scripting (XSS) vulnerability in the Contributed Packages for PyBlosxom 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the Comments plugin in the (1) url and (2) author fields. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61821 | CVE-2006-3142 | SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter. | 2 | 7.5 | High | 2016-12-20 | 2016-12-15 | View | |
62077 | CVE-2006-3399 | Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message, a variant of CVE-2004-1632. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
62333 | CVE-2006-3665 | SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certain of this. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16897 of 17672, showing 5 records out of 88360 total, starting on record 84481, ending on 84485