NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62040  CVE-2006-3362  Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.    5.1  Medium  2016-12-20  2011-03-07  View
62296  CVE-2006-3622  The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a " (single quote) in the p parameter, which displays the path in an error message. NOTE: it is not clear whether this is SQL injection or a forced SQL error.    Medium  2016-12-20  2008-09-05  View
62808  CVE-2006-4161  Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter.    Medium  2016-12-20  2008-09-05  View
63320  CVE-2006-4687  Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."    5.1  Medium  2016-12-20  2011-10-03  View
64344  CVE-2006-5769  Multiple cross-site scripting (XSS) vulnerabilities in admin.tool CMS 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fSid or (2) fSrcBegriffe parameters in unspecified vectors.    4.3  Medium  2016-12-20  2016-10-17  View

Page 3188 of 17672, showing 5 records out of 88360 total, starting on record 15936, ending on 15940

Actions