NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62919 | CVE-2006-4280 | ** DISPUTED ** PHP remote file inclusion vulnerability in anjel.index.php in ANJEL (formerly MaMML) Component (com_anjel) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by a third party, who says that $mosConfig_absolute_path is set in a configuration file. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63175 | CVE-2006-4542 | Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-09 | View | |
63431 | CVE-2006-4810 | Buffer overflow in the readline function in util/texindex.c, as used by the (1) texi2dvi and (2) texindex commands, in texinfo 4.8 and earlier allows local users to execute arbitrary code via a crafted Texinfo file. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
63687 | CVE-2006-5081 | PHP remote file inclusion vulnerability in acc.php in QuickBlogger (QB) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63943 | CVE-2006-5342 | Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.3 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_tune, aka Vuln# DB18. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB18 might be related to SQL injection in the EXTENT_OF function. | 2 | 7.1 | High | 2016-12-20 | 2012-10-22 | View |
Page 17341 of 17672, showing 5 records out of 88360 total, starting on record 86701, ending on 86705