NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72992 | CVE-2004-2615 | The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact. | 2 | 4.6 | Medium | 2016-12-20 | 2008-09-05 | View | |
58912 | CVE-2006-0172 | Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting. | 2 | 3.5 | Low | 2016-12-20 | 2011-03-07 | View | |
59168 | CVE-2006-0430 | Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown). | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
59424 | CVE-2006-0693 | Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59680 | CVE-2006-0957 | Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 180 of 17672, showing 5 records out of 88360 total, starting on record 896, ending on 900