NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61440 | CVE-2006-2755 | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
61696 | CVE-2006-3012 | SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61952 | CVE-2006-3273 | Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 rc1 allows remote attackers to inject arbitrary web script or HTML via the user parameter ("New Name" field). | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
62208 | CVE-2006-3534 | Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot dot (%2E%2E) sequences in an HTTP GET request for a file path containing "/content". | 2 | 7.8 | High | 2016-12-20 | 2011-03-07 | View | |
62464 | CVE-2006-3796 | DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View |
Page 416 of 17672, showing 5 records out of 88360 total, starting on record 2076, ending on 2080