NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62027 | CVE-2006-3349 | Multiple SQL injection vulnerabilities in SmS Script allow remote attackers to execute arbitrary SQL commands via the CatID parameter in (1) cat.php and (2) add.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 62795 | CVE-2006-4141 | SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby and (2) sortorder parameters. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 63307 | CVE-2006-4674 | Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 64075 | CVE-2006-5474 | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 65355 | CVE-2006-6812 | Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 2789 of 17672, showing 5 records out of 88360 total, starting on record 13941, ending on 13945