NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65459 | CVE-2006-6916 | Getahead Direct Web Remoting (DWR) before 1.1.3 allows attackers to cause a denial of service (infinite loop) via unknown vectors related to "crafted input." | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65716 | CVE-2006-7173 | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
73140 | CVE-2004-2763 | The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting. | 2 | 5.8 | Medium | 2016-12-20 | 2009-06-02 | View | |
58804 | CVE-2006-0064 | PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-08-23 | View | |
59060 | CVE-2006-0320 | SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 17225 of 17672, showing 5 records out of 88360 total, starting on record 86121, ending on 86125