NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61403  CVE-2006-2718  JIWA Financials 6.4.14 passes a Microsoft SQL Server account"s username and password, and the name of a data source, to a Crystal Reports .rpt file, which allows remote authenticated users to execute certain standard stored procedures by referencing them in a user-written .rpt file, as demonstrated by using a stored procedure that provides the username and cleartext password of every account.    6.5  Medium  2016-12-20  2008-09-05  View
61659  CVE-2006-2975  Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG. NOTE: portions of this description"s details are obtained from third party information.    2.6  Low  2016-12-20  2011-03-07  View
61915  CVE-2006-3236  Multiple SQL injection vulnerabilities in thinkWMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) index.php or (b) printarticle.php, and the (2) catid parameter in index.php.    7.5  High  2016-12-20  2011-03-07  View
62171  CVE-2006-3497  Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive.    5.1  Medium  2016-12-20  2011-04-07  View
62427  CVE-2006-3759  Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."    Medium  2016-12-20  2008-09-05  View

Page 17459 of 17672, showing 5 records out of 88360 total, starting on record 87291, ending on 87295

Actions