NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61725  CVE-2006-3041  ** DISPUTED ** PHP remote file inclusion vulnerability in Ltwcalendar/calendar.php in Codewalkers Ltwcalendar 4.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the ltw_config[include_dir] parameter. NOTE: CVE disputes this claim, since the $ltw_config[include_dir] variable is defined as a static value in an include file before it is referenced in an include() statement.    7.5  High  2016-12-20  2008-09-05  View
61981  CVE-2006-3302  PHP remote file inclusion vulnerability in mod_cbsms.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosC_a_path parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.    5.1  Medium  2016-12-20  2011-03-07  View
62237  CVE-2006-3563  Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.    2.6  Low  2016-12-20  2008-09-05  View
62493  CVE-2006-3825  The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication.    2.1  Low  2016-12-20  2011-03-07  View
62749  CVE-2006-4092  Simpliciti Locked Browser does not properly limit a user"s actions to ones within the intended Internet Explorer environment, which allows local users to perform unauthorized actions by visiting a web site that executes a JavaScript window.blur loop to remove focus from the browser window, then pressing CTRL-SHIFT-ESC to invoke the Task Manager.    3.6  Low  2016-12-20  2008-09-05  View

Page 1801 of 17672, showing 5 records out of 88360 total, starting on record 9001, ending on 9005

Actions