NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59942  CVE-2006-1228  Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.    5.1  Medium  2016-12-20  2008-09-05  View
60710  CVE-2006-2005  Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.    7.5  High  2016-12-20  2008-09-05  View
61478  CVE-2006-2793  SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.    7.5  High  2016-12-20  2008-09-05  View
61734  CVE-2006-3050  Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.    2.6  Low  2016-12-20  2008-09-05  View
62502  CVE-2006-3834  EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors.    Medium  2016-12-20  2008-09-05  View

Page 261 of 17672, showing 5 records out of 88360 total, starting on record 1301, ending on 1305

Actions