NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59593 | CVE-2006-0864 | filescan in Global Hauri ViRobot 2.0 20050817 does not verify the Cookie HTTP header, which allows remote attackers to gain administrative privileges via an arbitrary cookie value. | 2 | 10 | High | 2016-12-20 | 2011-03-07 | View | |
59849 | CVE-2006-1127 | Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60105 | CVE-2006-1396 | Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60361 | CVE-2006-1656 | vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root. | 2 | 7.2 | High | 2016-12-20 | 2008-09-05 | View | |
60617 | CVE-2006-1912 | MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17350 of 17672, showing 5 records out of 88360 total, starting on record 86746, ending on 86750