NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63982 | CVE-2006-5381 | Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ directory. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64750 | CVE-2006-6189 | SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65006 | CVE-2006-6461 | tr1.php in Yourfreeworld Stylish Text Ads Script allows remote attackers to obtain the installation path via an invalid id parameter, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2508. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View | |
65262 | CVE-2006-6718 | The Allied Telesis AT-9000/24 Ethernet switch has a default password for its admin account, "manager," which allows remote attackers to perform unauthorized actions. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65518 | CVE-2006-6975 | ** DISPUTED ** PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the class_pwd parameter. NOTE: this issue has been disputed by CVE and multiple third parties, who state that $class_pwd is set to a static value before the relevant include statement. | 2 | 5.1 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17540 of 17672, showing 5 records out of 88360 total, starting on record 87696, ending on 87700