NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 58670 | CVE-2007-6675 | The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows remote attackers to read the comments in restricted modules. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
| 59182 | CVE-2006-0444 | SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59438 | CVE-2006-0707 | PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable. | 2 | 5 | Medium | 2016-12-20 | 2013-01-03 | View | |
| 59694 | CVE-2006-0971 | Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59950 | CVE-2006-1236 | Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 3183 of 17672, showing 5 records out of 88360 total, starting on record 15911, ending on 15915