NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60409  CVE-2006-1704  Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.    Medium  2016-12-20  2008-09-05  View
61433  CVE-2006-2748  SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple vectors, as demonstrated by the (1) type parameter in adminfunctions.php and the (2) catalogue_id parameter in editcatalogue.php.    6.4  Medium  2016-12-20  2008-09-05  View
61689  CVE-2006-3005  The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.    Medium  2016-12-20  2008-09-05  View
63481  CVE-2006-4865  Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors.    Medium  2016-12-20  2008-09-05  View
63737  CVE-2006-5131  module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?php" and "?>", possibly due to a static code injection vulnerability involving admin/data_inc.php.    7.5  High  2016-12-20  2008-09-05  View

Page 17606 of 17672, showing 5 records out of 88360 total, starting on record 88026, ending on 88030

Actions