NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59426 | CVE-2006-0695 | Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59682 | CVE-2006-0959 | SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. NOTE: 1.04 has also been reported to be affected. | 2 | 7.5 | High | 2016-12-20 | 2011-08-05 | View | |
59938 | CVE-2006-1224 | Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
60194 | CVE-2006-1485 | gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60450 | CVE-2006-1745 | Cross-site scripting (XSS) vulnerability in login.php in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View |
Page 192 of 17672, showing 5 records out of 88360 total, starting on record 956, ending on 960