NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60613 | CVE-2006-1908 | Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
60869 | CVE-2006-2164 | Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php, and (2) prod_id parameter in (c) cart.php and (d) product_info.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries. | 2 | 7.5 | High | 2016-12-20 | 2008-11-03 | View | |
61125 | CVE-2006-2426 | Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory. | 2 | 6.4 | Medium | 2016-12-20 | 2013-09-11 | View | |
61381 | CVE-2006-2696 | Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
61637 | CVE-2006-2953 | Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow 2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the sqlType parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17328 of 17672, showing 5 records out of 88360 total, starting on record 86636, ending on 86640