NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63214 | CVE-2006-4581 | Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts. | 2 | 5 | Medium | 2016-12-20 | 2008-11-15 | View | |
63470 | CVE-2006-4854 | ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009. | 1 | 2016-12-20 | 2008-09-10 | View | |||
63726 | CVE-2006-5120 | Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View | |
63982 | CVE-2006-5381 | Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ directory. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
64238 | CVE-2006-5643 | Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17572 of 17672, showing 5 records out of 88360 total, starting on record 87856, ending on 87860