NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
56306 | CVE-2007-4175 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in OpenRat CMS 0.8-beta1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) subaction and (2) action parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2008-09-05 | View | |
59634 | CVE-2006-0907 | SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60146 | CVE-2006-1437 | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61170 | CVE-2006-2475 | Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View | |
61426 | CVE-2006-2741 | Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17563 of 17672, showing 5 records out of 88360 total, starting on record 87811, ending on 87815