NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60387 | CVE-2006-1682 | Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60643 | CVE-2006-1938 | Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60899 | CVE-2006-2195 | Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61155 | CVE-2006-2460 | Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61411 | CVE-2006-2726 | PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files via the config[fsBase] parameter in (1) drucken.php, (2) drucken2.php, (3) email_an_benutzer.php, (4) rechnung.php, (5) suche/search.php and (6) adminbereich/admin.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 17506 of 17672, showing 5 records out of 88360 total, starting on record 87526, ending on 87530