NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
62216 | CVE-2006-3542 | Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown Shopping Cart 0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) shop name field in (a) editshop.php, (b) edititem.php, and (c) index.php; and via the (2) item field in editshop.php and edititem.php. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
62472 | CVE-2006-3804 | Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) via a VCard attachment with a malformed base64 field, which copies more data than expected due to an integer underflow. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
63496 | CVE-2006-4880 | David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) footer.php, (2) template.php, or (3) lastvisit.php, which reveals the installation path in various error messages. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
63752 | CVE-2006-5146 | Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
65032 | CVE-2006-6487 | Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 329 of 17672, showing 5 records out of 88360 total, starting on record 1641, ending on 1645