NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59809 | CVE-2006-1087 | Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this vulnerability can be exploited by remote unauthenticated attackers in conjunction with the option[admin_pass] authentication bypass vulnerability. | 2 | 6.5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59810 | CVE-2006-1088 | PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59811 | CVE-2006-1089 | Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59812 | CVE-2006-1090 | register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations. | 2 | 7.8 | High | 2016-12-20 | 2011-03-07 | View | |
| 59813 | CVE-2006-1091 | Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors. | 2 | 7.8 | High | 2016-12-20 | 2008-09-05 | View |
Page 3333 of 17672, showing 5 records out of 88360 total, starting on record 16661, ending on 16665