NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59970 | CVE-2006-1256 | Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2 | 2.6 | Low | 2016-12-20 | 2011-03-07 | View | |
60226 | CVE-2006-1517 | sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60482 | CVE-2006-1777 | Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache error_log file, which is then included by doc/index.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
60738 | CVE-2006-2033 | PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter. NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
60994 | CVE-2006-2291 | Cross-site scripting (XSS) vulnerability in calendar_new.asp in IA-Calendar allows remote attackers to inject arbitrary web script or HTML via the TypeName1 parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 378 of 17672, showing 5 records out of 88360 total, starting on record 1886, ending on 1890