NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59183 | CVE-2006-0445 | index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "", which will display the full path of uploader.php. NOTE: this might be the result of a file inclusion vulnerability. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View | |
59439 | CVE-2006-0708 | Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476. | 2 | 9.3 | High | 2016-12-20 | 2011-03-07 | View | |
59695 | CVE-2006-0972 | SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
59951 | CVE-2006-1237 | Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60207 | CVE-2006-1498 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 267 of 17672, showing 5 records out of 88360 total, starting on record 1331, ending on 1335