NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
63810 | CVE-2006-5204 | Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin. | 2 | 2.1 | Low | 2016-12-20 | 2011-03-07 | View | |
64066 | CVE-2006-5465 | Buffer overflow in PHP before 5.2.0 allows remote attackers to execute arbitrary code via crafted UTF-8 inputs to the (1) htmlentities or (2) htmlspecialchars functions. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64322 | CVE-2006-5747 | Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
64578 | CVE-2006-6017 | WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display. | 2 | 4 | Medium | 2016-12-20 | 2008-09-05 | View | |
64834 | CVE-2006-6273 | sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid dir parameter, which reveals the path in an error message. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 381 of 17672, showing 5 records out of 88360 total, starting on record 1901, ending on 1905