NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 61984 | CVE-2006-3305 | Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau Webmail 2.7.10, and 2.7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) f_user parameter in index.php, the (2) pag parameter in messages.php, or the (3) lid, (4) tid, and (5) sid parameters in error.php. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
| 62240 | CVE-2006-3566 | search.results.php in HiveMail 3.1 and earlier allows remote attackers to obtain the installation path via certain manipulations related to the (1) searchdate and (2) folderids parameters. | 2 | 5 | Medium | 2016-12-20 | 2008-10-09 | View | |
| 62496 | CVE-2006-3828 | Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace." | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 62752 | CVE-2006-4096 | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is received after the recursion queue is empty. | 2 | 5 | Medium | 2016-12-20 | 2015-03-16 | View | |
| 63008 | CVE-2006-4369 | Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via an absolute pathname in the phpbb_root_path parameter. | 2 | 2.6 | Low | 2016-12-20 | 2016-10-17 | View |
Page 2587 of 17672, showing 5 records out of 88360 total, starting on record 12931, ending on 12935