NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59809  CVE-2006-1087  Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability.    6.5  Medium  2016-12-20  2011-03-07  View
59810  CVE-2006-1088  PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.    Medium  2016-12-20  2011-03-07  View
59811  CVE-2006-1089  Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.    4.3  Medium  2016-12-20  2011-03-07  View
59812  CVE-2006-1090  register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.    7.8  High  2016-12-20  2011-03-07  View
59813  CVE-2006-1091  Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.    7.8  High  2016-12-20  2008-09-05  View

Page 3333 of 17672, showing 5 records out of 88360 total, starting on record 16661, ending on 16665

Actions