NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59375 | CVE-2006-0644 | Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60399 | CVE-2006-1694 | SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61423 | CVE-2006-2738 | The open source version of Open-Xchange 0.8.2 and earlier uses a static default username and password with a valid login shell in the initfile for the ldap-server, which allows remote attackers to access any server where the default has not been changed. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61679 | CVE-2006-2995 | Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INCDIR parameter in (1) include/nav.php and (2) include/lang.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61935 | CVE-2006-3256 | SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 16897 of 17672, showing 5 records out of 88360 total, starting on record 84481, ending on 84485