NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58939  CVE-2006-0199  SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.    7.5  High  2016-12-20  2011-08-05  View
58940  CVE-2006-0200  Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.    9.3  High  2016-12-20  2011-03-07  View
58941  CVE-2006-0201  Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.    Medium  2016-12-20  2011-03-07  View
58942  CVE-2006-0202  Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.    3.6  Low  2016-12-20  2011-03-07  View
58943  CVE-2006-0203  membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.    Medium  2016-12-20  2011-10-03  View

Page 3159 of 17672, showing 5 records out of 88360 total, starting on record 15791, ending on 15795

Actions