NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64966 | CVE-2006-6421 | Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user. | 2 | 6 | Medium | 2016-12-20 | 2008-09-05 | View | |
65222 | CVE-2006-6678 | The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65478 | CVE-2006-6935 | SQL injection vulnerability in the login component in Portix-PHP 0.4.2 allows remote attackers to execute arbitrary SQL commands via the username and passwd (password) fields. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65735 | CVE-2006-7192 | Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag. | 2 | 4.3 | Medium | 2016-12-20 | 2008-11-13 | View | |
58823 | CVE-2006-0083 | Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17337 of 17672, showing 5 records out of 88360 total, starting on record 86681, ending on 86685