NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58944 | CVE-2006-0204 | Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 58945 | CVE-2006-0205 | Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts. | 2 | 5.1 | Medium | 2016-12-20 | 2011-09-06 | View | |
| 58946 | CVE-2006-0206 | Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php. | 2 | 7.5 | High | 2016-12-20 | 2016-11-28 | View | |
| 58947 | CVE-2006-0207 | Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function. | 2 | 5 | Medium | 2016-12-20 | 2011-09-09 | View | |
| 58948 | CVE-2006-0208 | Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message. | 2 | 2.6 | Low | 2016-12-20 | 2011-09-13 | View |
Page 3160 of 17672, showing 5 records out of 88360 total, starting on record 15796, ending on 15800