NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62668 | CVE-2006-4010 | SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vectors are covered by CVE-2006-3139. | 2 | 7.5 | High | 2016-12-20 | 2009-08-25 | View | |
62924 | CVE-2006-4285 | PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. NOTE: it was later reported that 2.1.5 is also affected. | 2 | 7.5 | High | 2016-12-20 | 2011-08-22 | View | |
63180 | CVE-2006-4547 | Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a " (single quote) character in the name, which reveals the details of the underlying SQL query, possibly because of a forced SQL error or SQL injection. | 2 | 6.5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63436 | CVE-2006-4819 | Heap-based buffer overflow in Opera 9.0 and 9.01 allows remote attackers to execute arbitrary code via a long URL in a tag (long link address). | 2 | 5.1 | Medium | 2016-12-20 | 2012-06-08 | View | |
63692 | CVE-2006-5086 | Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17370 of 17672, showing 5 records out of 88360 total, starting on record 86846, ending on 86850