NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58954 | CVE-2006-0214 | Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls. | 2 | 7.5 | High | 2016-12-20 | 2008-09-20 | View | |
| 61002 | CVE-2006-2300 | Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 62026 | CVE-2006-3348 | Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in report.php and (2) level parameter in custom_buttons.php. | 2 | 7.5 | High | 2016-12-20 | 2008-10-09 | View | |
| 63562 | CVE-2006-4954 | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users. | 2 | 7.5 | High | 2016-12-20 | 2016-11-28 | View | |
| 64074 | CVE-2006-5473 | ** DISPUTED ** PHP remote file inclusion vulnerability in Description.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the lib_dir parameter. NOTE: this issue is disputed by CVE as of 20061023, since there is no Description.php file included in the product, and the existing "Description" file contains documentation, not functioning code. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 2777 of 17672, showing 5 records out of 88360 total, starting on record 13881, ending on 13885