NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63282  CVE-2006-4649  PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.    7.5  High  2016-12-20  2011-08-23  View
63538  CVE-2006-4923  Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter.    4.3  Medium  2016-12-20  2011-03-07  View
63794  CVE-2006-5188  Directory traversal vulnerability in download.php in webGENEius GOOP Gallery 2.0.2 allows remote attackers to read or list data from certain files or directories via unspecified vectors.    Medium  2016-12-20  2008-09-05  View
64050  CVE-2006-5449  procmail in Ingo H3 before 1.1.2 Horde module allows remote authenticated users to execute arbitrary commands via shell metacharacters in the mailbox destination of a filter rule.    6.5  Medium  2016-12-20  2011-03-07  View
64306  CVE-2006-5731  Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php.    6.4  Medium  2016-12-20  2011-03-07  View

Page 3065 of 17672, showing 5 records out of 88360 total, starting on record 15321, ending on 15325

Actions