NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58957 | CVE-2006-0217 | Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59213 | CVE-2006-0475 | PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59469 | CVE-2006-0738 | Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m field (media name and transport address). | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59981 | CVE-2006-1267 | Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request. | 2 | 5.1 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 61005 | CVE-2006-2303 | Cross-Application Scripting (XAS) vulnerability in ICQ Client 5.04 build 2321 and earlier allows remote attackers to inject arbitrary web script from one application into another via a banner, which is processed in the My Computer zone using the Internet Explorer COM object. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 2792 of 17672, showing 5 records out of 88360 total, starting on record 13956, ending on 13960