NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60484 | CVE-2006-1779 | Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
60740 | CVE-2006-2035 | Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a "/?" sequence to a URL. | 2 | 3.7 | Low | 2016-12-20 | 2008-09-05 | View | |
60996 | CVE-2006-2293 | SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61252 | CVE-2006-2557 | PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61508 | CVE-2006-2823 | Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) admin/scart.mdb and possibly (2) admin/scart97.mdb. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 390 of 17672, showing 5 records out of 88360 total, starting on record 1946, ending on 1950