NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61752  CVE-2006-3069  ** DISPUTED ** PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, as demonstrated by (1) index.php, (2) faq.php, and (3) hardware.php. NOTE: this issue has been disputed by multiple third-party researchers, who state that config[private] is initialized in an include file before being used.    7.5  High  2016-12-20  2008-09-05  View
62776  CVE-2006-4122  Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php.    7.5  High  2016-12-20  2011-03-07  View
63032  CVE-2006-4394  A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors.    7.5  High  2016-12-20  2011-03-07  View
65336  CVE-2006-6792  SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.    7.5  High  2016-12-20  2011-03-07  View
825  CVE-2008-0854  SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.    7.5  High  2017-01-03  2008-09-05  View

Page 2579 of 17672, showing 5 records out of 88360 total, starting on record 12891, ending on 12895

Actions