NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64306 | CVE-2006-5731 | Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
64818 | CVE-2006-6257 | The file manager in AlternC 0.9.5 and earlier, when warnings are enabled in PHP, allows remote attackers to obtain sensitive information via certain folder names such as ones composed of JavaScript code, which reveal the path in a warning message. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
65330 | CVE-2006-6786 | Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
51 | CVE-2008-0059 | Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic." | 2 | 5.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
307 | CVE-2008-0329 | LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 1834 of 17672, showing 5 records out of 88360 total, starting on record 9166, ending on 9170