NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60742 | CVE-2006-2037 | Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
60998 | CVE-2006-2295 | Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61254 | CVE-2006-2559 | Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61510 | CVE-2006-2825 | cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user"s own open_basedir directive, but not the main server"s open_basedir directive. | 2 | 5.1 | Medium | 2016-12-20 | 2008-11-15 | View | |
61766 | CVE-2006-3083 | The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion. | 2 | 7.2 | High | 2016-12-20 | 2011-07-18 | View |
Page 402 of 17672, showing 5 records out of 88360 total, starting on record 2006, ending on 2010