NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60654 | CVE-2006-1949 | SQL injection vulnerability in plexcart.pl in NicPlex PlexCart X3 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-11-03 | View | |
60910 | CVE-2006-2206 | The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting passwords. | 2 | 10 | High | 2016-12-20 | 2008-09-05 | View | |
61166 | CVE-2006-2471 | Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers, including (1) DNS and IP addresses to address to T3 clients, (2) internal sensitive information using GetIORServlet, (3) certain "server details" in exceptions when invalid XML is provided, and (4) a stack trace in a SOAP fault. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
61422 | CVE-2006-2737 | utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61678 | CVE-2006-2994 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in phazizGuestbook 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) url fields, and (4) text field (content parameter). | 2 | 5.8 | Medium | 2016-12-20 | 2011-09-13 | View |
Page 17570 of 17672, showing 5 records out of 88360 total, starting on record 87846, ending on 87850