NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58630 | CVE-2007-6635 | FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in cleartext in a database, which might allow context-dependent attackers to obtain the password via unspecified database access. | 2 | 6.4 | Medium | 2017-01-07 | 2008-09-05 | View | |
| 58886 | CVE-2006-0146 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-06-14 | View | |
| 59142 | CVE-2006-0404 | Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59398 | CVE-2006-0667 | lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59654 | CVE-2006-0927 | Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View |
Page 2619 of 17672, showing 5 records out of 88360 total, starting on record 13091, ending on 13095