NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 65655 | CVE-2006-7112 | Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it. | 2 | 6 | Medium | 2016-12-20 | 2009-03-16 | View | |
| 65659 | CVE-2006-7116 | SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id parameter ($id variable) to index.php. | 2 | 7.5 | High | 2016-12-20 | 2009-03-16 | View | |
| 65660 | CVE-2006-7117 | Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie to index.php, which is not properly handled by includes/head.php; and (2) read arbitrary files via ".." sequences in the file parameter in an add_dl action to adm_index.php, as demonstrated by reading connect.php. | 2 | 6.8 | Medium | 2016-12-20 | 2009-03-16 | View | |
| 65661 | CVE-2006-7118 | SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter. | 2 | 7.5 | High | 2016-12-20 | 2009-03-16 | View | |
| 65673 | CVE-2006-7130 | PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter, a different vector than CVE-2006-6770. | 2 | 7.5 | High | 2016-12-20 | 2009-03-16 | View |
Page 2856 of 17672, showing 5 records out of 88360 total, starting on record 14276, ending on 14280