NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 61227 | CVE-2006-2532 | stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter, which displays the path in an error message. NOTE: this issue was originally claimed to be SQL injection, but CVE analysis shows that the problem is related to an invalid value that prevents some variables from being set. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 61483 | CVE-2006-2798 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 61739 | CVE-2006-3055 | Multiple SQL injection vulnerabilities in VBZooM 1.02 allow remote attackers to execute arbitrary SQL commands via the (1) QuranID, (2) ShowByQuranID, or (3) Action parameters to meaning.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 61995 | CVE-2006-3317 | PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 62251 | CVE-2006-3577 | SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 3334 of 17672, showing 5 records out of 88360 total, starting on record 16666, ending on 16670