NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60054 | CVE-2006-1345 | polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an "option[]=null" parameter value, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
62358 | CVE-2006-3690 | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) components/com_minibb.php or (2) components/minibb/index.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63382 | CVE-2006-4758 | phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View | |
64150 | CVE-2006-5549 | ** DISPUTED ** PHP remote file inclusion vulnerability in libraries/amfphp/amf-core/custom/CachedGateway.php in Adobe PHP SDK allows remote attackers to execute arbitrary PHP code via the AMFPHP_BASE parameter. NOTE: this issue has been disputed by a third-party researcher who states that AMFPHP_BASE is a constant. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64406 | CVE-2006-5831 | PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the load_page parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 16989 of 17672, showing 5 records out of 88360 total, starting on record 84941, ending on 84945