NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59609  CVE-2006-0880  Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah"s Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.    4.3  Medium  2016-12-20  2011-03-07  View
59610  CVE-2006-0881  Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah"s Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.    7.5  High  2016-12-20  2011-03-07  View
59611  CVE-2006-0882  Directory traversal vulnerability in include.php in Noah"s Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.    Medium  2016-12-20  2011-03-07  View
59612  CVE-2006-0883  OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.    Medium  2016-12-20  2011-08-26  View
59613  CVE-2006-0884  The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.    9.3  High  2016-12-20  2011-05-25  View

Page 3293 of 17672, showing 5 records out of 88360 total, starting on record 16461, ending on 16465

Actions