NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61827 | CVE-2006-3148 | SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62083 | CVE-2006-3405 | Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters. | 2 | 5.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
62339 | CVE-2006-3671 | Cross-site request forgery (CSRF) vulnerability in the communicate function in estmaster.c for Hyper Estraier before 1.3.3 allows remote attackers to perform unauthorized actions as other users via unknown vectors. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62595 | CVE-2006-3937 | post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
62851 | CVE-2006-4210 | nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View |
Page 16933 of 17672, showing 5 records out of 88360 total, starting on record 84661, ending on 84665