NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64936 | CVE-2006-6390 | Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the config[db_type] parameter to (1) categories.php, (2) couriers.php, (3) orders.php, and (4) products.php in actions_admin/; and (5) orders.php and (6) products.php in actions_client/; as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by one of these PHP scripts. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
65192 | CVE-2006-6648 | PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65448 | CVE-2006-6905 | Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | 2 | 10 | High | 2016-12-20 | 2008-11-15 | View | |
65705 | CVE-2006-7162 | PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files. | 2 | 1.9 | Low | 2016-12-20 | 2008-09-05 | View | |
73129 | CVE-2004-2752 | Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17159 of 17672, showing 5 records out of 88360 total, starting on record 85791, ending on 85795