NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61949  CVE-2006-3270  SQL injection vulnerability in cms_admin.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via multiple unspecified parameters, such as the add_link_mid parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.    7.5  High  2016-12-20  2011-03-07  View
62205  CVE-2006-3531  includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.    7.5  High  2016-12-20  2011-03-07  View
62461  CVE-2006-3793  PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SD_DIR parameter.    5.1  Medium  2016-12-20  2011-03-07  View
62717  CVE-2006-4060  PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.    7.5  High  2016-12-20  2011-03-07  View
62973  CVE-2006-4334  Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.    Medium  2016-12-20  2013-09-05  View

Page 17535 of 17672, showing 5 records out of 88360 total, starting on record 87671, ending on 87675

Actions