NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62360  CVE-2006-3692  ** DISPUTED ** PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating that the $lm_path variable is set to a constant value. As of 20060726, CVE concurs with the vendor based on SecurityTracker"s post-disclosure analysis.    7.5  High  2016-12-20  2008-09-05  View
62872  CVE-2006-4231  IrfanView 3.98 (with plugins) allows remote attackers to cause a denial of service (application crash) via a crafted CUR image file.    2.6  Low  2016-12-20  2008-09-05  View
63896  CVE-2006-5293  Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah"s Classifieds 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the frommethod parameter.    6.8  Medium  2016-12-20  2008-09-05  View
64920  CVE-2006-6374  Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files.    7.5  High  2016-12-20  2008-09-05  View
1433  CVE-2008-1486  SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands via the non-fulltext search.    6.8  Medium  2017-01-03  2008-09-05  View

Page 17002 of 17672, showing 5 records out of 88360 total, starting on record 85006, ending on 85010

Actions