NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62360 | CVE-2006-3692 | ** DISPUTED ** PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating that the $lm_path variable is set to a constant value. As of 20060726, CVE concurs with the vendor based on SecurityTracker"s post-disclosure analysis. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62872 | CVE-2006-4231 | IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
63896 | CVE-2006-5293 | Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah"s Classifieds 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the frommethod parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
64920 | CVE-2006-6374 | Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
1433 | CVE-2008-1486 | SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands via the non-fulltext search. | 2 | 6.8 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 17002 of 17672, showing 5 records out of 88360 total, starting on record 85006, ending on 85010