NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60612 | CVE-2006-1907 | Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60868 | CVE-2006-2163 | Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
61124 | CVE-2006-2425 | Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
61380 | CVE-2006-2695 | admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory. | 2 | 5.1 | Medium | 2016-12-20 | 2013-09-10 | View | |
61636 | CVE-2006-2952 | Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) Default_Theme parameter to header.php or (2) ModPath parameter to modules/cluster-paradise/cluster-E.php. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17322 of 17672, showing 5 records out of 88360 total, starting on record 86606, ending on 86610