NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60999 | CVE-2006-2296 | SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61255 | CVE-2006-2560 | Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | 2 | 7.5 | High | 2016-12-20 | 2013-01-24 | View | |
61511 | CVE-2006-2826 | SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61767 | CVE-2006-3084 | The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE: as of 20060808, it is not known whether an exploitable attack scenario exists for these issues. | 2 | 7.2 | High | 2016-12-20 | 2011-07-25 | View | |
62023 | CVE-2006-3345 | Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and earlier, allows remote attackers to inject arbitrary web script or HTML via a chat line. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 408 of 17672, showing 5 records out of 88360 total, starting on record 2036, ending on 2040