NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
63307  CVE-2006-4674  Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.    7.5  High  2016-12-20  2008-09-05  View
63563  CVE-2006-4955  Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.    Medium  2016-12-20  2016-11-28  View
63819  CVE-2006-5213  Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).    3.6  Low  2016-12-20  2011-03-07  View
64075  CVE-2006-5474  The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.    7.5  High  2016-12-20  2008-09-05  View
64331  CVE-2006-5756  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2006. Notes: none.        2016-12-20  2008-09-10  View

Page 433 of 17672, showing 5 records out of 88360 total, starting on record 2161, ending on 2165

Actions