NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60630 | CVE-2006-1925 | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
60886 | CVE-2006-2181 | Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php. | 2 | 4.3 | Medium | 2016-12-20 | 2011-09-13 | View | |
61142 | CVE-2006-2443 | The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View | |
61398 | CVE-2006-2713 | Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEID of a protected asset, which can be used in other attacks against AVR. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61654 | CVE-2006-2970 | videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain sensitive information via a certain id parameter, probably with an invalid value, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17429 of 17672, showing 5 records out of 88360 total, starting on record 87141, ending on 87145