NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60146 | CVE-2006-1437 | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
60402 | CVE-2006-1697 | Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60914 | CVE-2006-2211 | Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61426 | CVE-2006-2741 | Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
61938 | CVE-2006-3259 | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment). | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17201 of 17672, showing 5 records out of 88360 total, starting on record 86001, ending on 86005