NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58107 | CVE-2007-6098 | Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for attackers with physical access to guess valid login credentials while avoiding detection. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
58875 | CVE-2006-0135 | SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable). | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59643 | CVE-2006-0916 | Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user"s browser to send the form data to another domain. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60411 | CVE-2006-1706 | Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60667 | CVE-2006-1962 | SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php. | 2 | 7.5 | High | 2016-12-20 | 2011-08-05 | View |
Page 17209 of 17672, showing 5 records out of 88360 total, starting on record 86041, ending on 86045