NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61406 | CVE-2006-2721 | Cross-site scripting (XSS) vulnerability in news.php in VARIOMAT allows remote attackers to inject arbitrary HTML or web script via the subcat parameter. NOTE: this issue might be resultant from SQL injection. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
61918 | CVE-2006-3239 | SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62430 | CVE-2006-3762 | The Touch Control ActiveX control 2.0.0.55 allows remote attackers to read and possibly execute arbitrary files via a "file///" URI in the sPath parameter to the Execute function. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
62942 | CVE-2006-4303 | Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun Solaris 10 allows remote attackers to cause a denial of service ("tight loop" and CPU consumption for listener applications) via unknown vectors related to TCP fusion (do_tcp_fusion). | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
63454 | CVE-2006-4837 | Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 17446 of 17672, showing 5 records out of 88360 total, starting on record 87226, ending on 87230