NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58939 | CVE-2006-0199 | SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-08-05 | View | |
| 58940 | CVE-2006-0200 | Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages. | 2 | 9.3 | High | 2016-12-20 | 2011-03-07 | View | |
| 58941 | CVE-2006-0201 | Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 58942 | CVE-2006-0202 | Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data. | 2 | 3.6 | Low | 2016-12-20 | 2011-03-07 | View | |
| 58943 | CVE-2006-0203 | membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter. | 2 | 5 | Medium | 2016-12-20 | 2011-10-03 | View |
Page 3159 of 17672, showing 5 records out of 88360 total, starting on record 15791, ending on 15795