NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60409 | CVE-2006-1704 | Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61433 | CVE-2006-2748 | SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple vectors, as demonstrated by the (1) type parameter in adminfunctions.php and the (2) catalogue_id parameter in editcatalogue.php. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
61689 | CVE-2006-3005 | The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63481 | CVE-2006-4865 | Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63737 | CVE-2006-5131 | module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?php" and "?>", possibly due to a static code injection vulnerability involving admin/data_inc.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 17606 of 17672, showing 5 records out of 88360 total, starting on record 88026, ending on 88030