NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
58886  CVE-2006-0146  The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.    7.5  High  2016-12-20  2011-06-14  View
59142  CVE-2006-0404  Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords.    Medium  2016-12-20  2011-03-07  View
59398  CVE-2006-0667  lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.    4.6  Medium  2016-12-20  2011-03-07  View
59654  CVE-2006-0927  Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.    2.6  Low  2016-12-20  2008-09-05  View
59910  CVE-2006-1196  Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.    4.3  Medium  2016-12-20  2011-03-07  View

Page 35 of 17672, showing 5 records out of 88360 total, starting on record 171, ending on 175

Actions