NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60411 | CVE-2006-1706 | Multiple SQL injection vulnerabilities in Shopweezle 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) itemID parameter to (a) login.php and (b) memo.php; and the (2) itemgr, (3) brandID, and (4) album parameters to (c) index.php. NOTE: this issue also produces resultant full path disclosure from invalid SQL queries. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60667 | CVE-2006-1962 | SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php. | 2 | 7.5 | High | 2016-12-20 | 2011-08-05 | View | |
60923 | CVE-2006-2220 | phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message. | 2 | 5 | Medium | 2016-12-20 | 2016-10-17 | View | |
61179 | CVE-2006-2484 | Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
61435 | CVE-2006-2750 | Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts or HTML via failed SQL queries, which is reflected in an error message. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 17646 of 17672, showing 5 records out of 88360 total, starting on record 88226, ending on 88230