NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
65056 | CVE-2006-6511 | dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php). | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
65312 | CVE-2006-6768 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) main parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65569 | CVE-2006-7026 | PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter, a different vector than CVE-2006-2149. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
72993 | CVE-2004-2616 | The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message. | 2 | 4 | Medium | 2016-12-20 | 2016-10-17 | View | |
58913 | CVE-2006-0173 | Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content. | 2 | 4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 185 of 17672, showing 5 records out of 88360 total, starting on record 921, ending on 925