NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60742  CVE-2006-2037  Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter.    4.3  Medium  2016-12-20  2008-09-05  View
60998  CVE-2006-2295  Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.    7.5  High  2016-12-20  2011-03-07  View
61254  CVE-2006-2559  Linksys WRT54G Wireless-G Broadband Router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic.    7.5  High  2016-12-20  2011-03-07  View
61510  CVE-2006-2825  cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user"s own open_basedir directive, but not the main server"s open_basedir directive.    5.1  Medium  2016-12-20  2008-11-15  View
61766  CVE-2006-3083  The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privileges by causing setuid to fail to drop privileges using attacks such as resource exhaustion.    7.2  High  2016-12-20  2011-07-18  View

Page 402 of 17672, showing 5 records out of 88360 total, starting on record 2006, ending on 2010

Actions