NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64306 | CVE-2006-5731 | Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
64562 | CVE-2006-5987 | SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote attackers to execute arbitrary SQL commands via the a parameter. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
64818 | CVE-2006-6257 | The file manager in AlternC 0.9.5 and earlier, when warnings are enabled in PHP, allows remote attackers to obtain sensitive information via certain folder names such as ones composed of JavaScript code, which reveal the path in a warning message. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
65074 | CVE-2006-6529 | The Chatroom Module before 4.7.x.-1.0 for Drupal displays private messages in a chatroom"s last messages overview, which allows remote attackers to obtain sensitive information by reading the overview. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
65330 | CVE-2006-6786 | Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 288 of 17672, showing 5 records out of 88360 total, starting on record 1436, ending on 1440