NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 63528 | CVE-2006-4913 | Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 64040 | CVE-2006-5439 | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Misc Tools 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 7.5 | High | 2016-12-20 | 2011-08-23 | View | |
| 64552 | CVE-2006-5977 | Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via the (1) M or (2) Y parameter to rss_out.asp, or the (3) cate parameter to all_calendars.asp. NOTE: the all_calendars.asp/calsids vector is already covered by CVE-2006-2293. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 64808 | CVE-2006-6247 | Multiple SQL injection vulnerabilities in Uapplication UPhotoGallery 1.1 allow remote attackers to execute arbitrary SQL commands via the ci parameter to (1) slideshow.asp or (2) thumbnails.asp. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 65064 | CVE-2006-6519 | SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 2395 of 17672, showing 5 records out of 88360 total, starting on record 11971, ending on 11975