NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59182 | CVE-2006-0444 | SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
59438 | CVE-2006-0707 | PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable. | 2 | 5 | Medium | 2016-12-20 | 2013-01-03 | View | |
59694 | CVE-2006-0971 | Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60206 | CVE-2006-1497 | Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61230 | CVE-2006-2535 | index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might be resultant from a more serious issue such as directory traversal. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1691 of 17672, showing 5 records out of 88360 total, starting on record 8451, ending on 8455