NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61434 | CVE-2006-2749 | SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary SQL commands via the (1) txtCustomField and (2) CustomFieldID array parameters. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
61690 | CVE-2006-3006 | Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
61946 | CVE-2006-3267 | SQL injection vulnerability in index.php in Infinite Core Technologies (ICT) 1.0 Gold and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62202 | CVE-2006-3528 | Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) image_upload.php and (2) file_upload.php. | 2 | 6.8 | Medium | 2016-12-20 | 2016-10-17 | View | |
62458 | CVE-2006-3790 | The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that is inconsistent with the packet size, which leads to a buffer over-read. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17370 of 17672, showing 5 records out of 88360 total, starting on record 86846, ending on 86850