NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64310 | CVE-2006-5735 | Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the language parameter, related to register.php storing a language value in the users table. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64566 | CVE-2006-5991 | Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prodtype parameter in prodtype.asp and the (2) product parameter in product.asp. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64822 | CVE-2006-6261 | Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a) NumberofEntries, (b) Length (aka Length1), (c) Filename (aka File1), (d) Title (aka Title1) field, or other unspecified fields. | 2 | 9.3 | High | 2016-12-20 | 2011-03-07 | View | |
65078 | CVE-2006-6533 | Directory traversal vulnerability in admin/templates_boxes_layout.php in osCommerce 3.0a3 allows remote attackers to include and execute arbitrary PHP files via a .. (dot dot) in the filter parameter. NOTE: this issue can be leveraged to obtain full path information in error messages. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
65334 | CVE-2006-6790 | Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 311 of 17672, showing 5 records out of 88360 total, starting on record 1551, ending on 1555