NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59389 | CVE-2006-0658 | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt. | 2 | 5 | Medium | 2016-12-20 | 2011-10-12 | View | |
| 59390 | CVE-2006-0659 | Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen enabled, allow remote attackers to execute arbitrary code via the bbPath[path] parameter in (1) class.forumposts.php and (2) forumpollrenderer.php. | 2 | 6.8 | Medium | 2016-12-20 | 2011-09-08 | View | |
| 59391 | CVE-2006-0660 | Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59392 | CVE-2006-0661 | Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59393 | CVE-2006-0662 | Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 3249 of 17672, showing 5 records out of 88360 total, starting on record 16241, ending on 16245