NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 63282 | CVE-2006-4649 | PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-08-23 | View | |
| 63538 | CVE-2006-4923 | Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 63794 | CVE-2006-5188 | Directory traversal vulnerability in download.php in webGENEius GOOP Gallery 2.0.2 allows remote attackers to read or list data from certain files or directories via unspecified vectors. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 64050 | CVE-2006-5449 | procmail in Ingo H3 before 1.1.2 Horde module allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox destination of a filter rule. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 64306 | CVE-2006-5731 | Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 3065 of 17672, showing 5 records out of 88360 total, starting on record 15321, ending on 15325